Medium severity6.1NVD Advisory· Published May 31, 2018· Updated Jun 17, 2026
CVE-2016-10547
CVE-2016-10547
Description
Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the keys, such as name[]=, it is possible to bypass autoescaping and inject content into the DOM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nunjucksnpm | < 2.4.3 | 2.4.3 |
Affected products
3- HackerOne/nunjucks node modulev5Range: <=2.4.2
Patches
Vulnerability mechanics
References
5- github.com/mozilla/nunjucks/issues/835nvdExploitThird Party AdvisoryWEB
- nodesecurity.io/advisories/147nvdExploitThird Party Advisory
- github.com/advisories/GHSA-f7ph-p5rv-phw2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-10547ghsaADVISORY
- www.npmjs.com/advisories/147ghsaWEB
News mentions
0No linked articles in our index yet.