VYPR
Critical severity9.8NVD Advisory· Published Apr 25, 2022· Updated Jun 17, 2026

CVE-2022-29078

CVE-2022-29078

Description

The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ejsnpm
< 3.1.73.1.7

Affected products

3
  • cpe:2.3:a:ejs:ejs:3.1.6:*:*:*:*:node.js:*:*
  • ejs/Embedded JavaScript templatesdescription
  • ghsa-coords
    Range: < 3.1.7

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.