Arbitrary local file read vulnerability during template rendering - swig-templates
- Severity:
- High
Description
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.0.4
References
Related Issues
- Arbitrary local file read vulnerability during template rendering - CVE-2023-25345
- obsidian-local-rest-api: Authenticated path traversal via URL-encoded %2F in /vault/{path} — arbitrary host file read/wr - Vulnerability
- Gatsby develop server has Local File Inclusion vulnerability - CVE-2023-34238
- FUXA vulnerable to Local File Inclusion - CVE-2023-31716
You might also like:
- Tags:
- npm
- swig-templates
Anything's wrong? Let us know Last updated on March 20, 2023


