Vulnerability library
Security checkMarch 20, 2023

Arbitrary local file read vulnerability during template rendering - swig-templates

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmswig-templates

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.

Recommendation

No fix is available yet. Followings are affected versions:

  • <= 2.0.4

References

Could your website be exposed too?

SmartScanner can check your website for Arbitrary local file read vulnerability during template rendering - swig-templates and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated March 20, 2023