Description
If a remote attacker was able to control the pretty option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend.
Recommendation
Update the pug package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.1
- Patched version(s): 3.0.1
References
Related Issues
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Remote code execution in handlebars when compiling templates - CVE-2021-23369
- Authenticated Remote Code Execution via loadReader functionName code injection in DbGate - CVE-2026-47670
- DbGate: Unauthenticated Remote Code Execution via JSON Script Runner - CVE-2026-47668
You might also like:
- Tags:
- npm
- pug
Anything's wrong? Let us know Last updated on May 28, 2025


