Headline
GHSA-mf6x-hrgr-658f: Eta vulnerable to Code Injection via templates rendered with user-defined data
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. Note: This is exploitable only for users who are rendering templates with user-defined data.
Eta vulnerable to Code Injection via templates rendered with user-defined data
High severity GitHub Reviewed Published Jan 30, 2023 to the GitHub Advisory Database • Updated Feb 1, 2023
Related news
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.