question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Please update "ejs": Security vulnerability, template injection.

See original GitHub issue

After running the npm audit, the report shows 2 high-security vulnerabilities for version 3.1.6 of ejs that gluegun depends on. It requires version ^3.1.7

npm audit report

ejs ❤️.1.7 Severity: high Template injection in ejs -https://github.com/advisories/GHSA-phwq-j96m-2c2q fix available via npm audit fix --force Will install gluegun@0.0.1, which is a breaking change node_modules/ejs gluegun >=0.3.0 Depends on vulnerable versions of ejs node_modules/gluegun

2 high severity vulnerabilities

Issue Analytics

  • State:open
  • Created a year ago
  • Comments:5

github_iconTop GitHub Comments

1reaction
bennetthardwickcommented, Aug 29, 2022

Not sure why the original was closed but I’ve opened #764 to bump ejs to 3.1.8.

1reaction
Cognetercommented, May 8, 2022

I second that. Please update gluegun’s ejs dependency version to 3.1.7.

Added a pull request for that: https://github.com/infinitered/gluegun/pull/759

Read more comments on GitHub >

github_iconTop Results From Across the Web

Security vulnerability Template injection in ejs #7161 - GitHub
Version 5.0.1 Environment info System: OS: Windows 10 10.0.19042 CPU: (16) x64 AMD Ryzen 7 4800H with Radeon Graphics Binaries: Node: ...
Read more >
ejs template injection vulnerability
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view ...
Read more >
CVE-2022-29078 ejs: server-side template injection in ...
A Command injection attack was found in ejs (Embedded JavaScript templates) for Node.js, which allows an attacker to execute server-side ...
Read more >
resolution - Running 'npm update ejs --depth 2', to fix security ...
It tells me # Run npm update ejs --depth 2 to resolve 1 vulnerability . This is the description tabel: High │ Template...
Read more >
Attack: Node.JS EJS Module RCE CVE-2022-29078
This signature detects attempts to exploit vulnerability in Node.js ejs module. ... server-side template injection which leads to remote code execution ...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found