Critical severity9.8NVD Advisory· Published Nov 17, 2017· Updated Jun 17, 2026
CVE-2017-1000228
CVE-2017-1000228
Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ejsnpm | < 2.5.5 | 2.5.5 |
Affected products
2Patches
Vulnerability mechanics
References
5- snyk.io/vuln/npm:ejs:20161128nvdExploitTechnical DescriptionThird Party AdvisoryWEB
- www.securityfocus.com/bid/101897nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-3w5v-p54c-f74xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-1000228ghsaADVISORY
- web.archive.org/web/20171123041219/http://www.securityfocus.com/bid/101897ghsaWEB
News mentions
0No linked articles in our index yet.