Description
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Recommendation
Update the ejs package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.1.10
- Patched version(s): 3.1.10
References
Related Issues
- akbr patch-into was discovered to contain a prototype pollution via the function patchInto - CVE-2024-38991
- vue-i18n has cross-site scripting vulnerability with prototype pollution - CVE-2024-52809
- @intlify/shared Prototype Pollution vulnerability - @intlify/shared - CVE-2024-52810
- @intlify/shared Prototype Pollution vulnerability - @intlify/vue-i18n-core - CVE-2024-52810
You might also like:
- Tags:
- npm
- ejs
Anything's wrong? Let us know Last updated on August 02, 2024


