Vulnerabilities/

Arbitrary local file read vulnerability during template rendering - swig-templates

Severity:
High

Description

Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
swig-templates
Anything's wrong? Let us know Last updated on March 20, 2023