Vulnerabilities/

ejs is vulnerable to remote code execution due to weak input validation

Severity:
High

Description

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

Recommendation

Update the ejs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
ejs
Anything's wrong? Let us know Last updated on September 08, 2023

This issue is available in SmartScanner Professional

See Pricing