Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mf6x-hrgr-658f: Eta vulnerable to Code Injection via templates rendered with user-defined data

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. Note: This is exploitable only for users who are rendering templates with user-defined data.

ghsa
#git#rce

Eta vulnerable to Code Injection via templates rendered with user-defined data

High severity GitHub Reviewed Published Jan 30, 2023 to the GitHub Advisory Database • Updated Feb 1, 2023

Related news

CVE-2022-25967

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.