Vulnerabilities/

@blakeembrey/template vulnerable to code injection when attacker controls template input

Severity:
Medium

Description

It is possible to inject and run code within the template if the attacker has access to write the template name.

Recommendation

Update the @blakeembrey/template package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@blakeembrey/template
Anything's wrong? Let us know Last updated on November 18, 2024