VYPR
Medium severity5.4NVD Advisory· Published Sep 21, 2021· Updated Jun 17, 2026

CVE-2021-23443

CVE-2021-23443

Description

This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization when the input to be rendered is an array (instead of a string or a SafeValue), even if {{ }} are used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
edge.jsnpm
< 5.3.25.3.2

Affected products

3
  • cpe:2.3:a:adonisjs:edge:*:*:*:*:*:node.js:*:*
    Range: <5.3.2
  • edge.js/edge.jsdescription
  • ghsa-coords
    Range: < 5.3.2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.