VYPR
Critical severity9.8NVD Advisory· Published Nov 17, 2017· Updated May 13, 2026

CVE-2017-1000228

CVE-2017-1000228

Description

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ejsnpm
< 2.5.52.5.5

Affected products

1
  • cpe:2.3:a:ejs:ejs:*:*:*:*:*:*:*:*
    Range: <2.5.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.