VYPR
High severityNVD Advisory· Published Feb 1, 2023· Updated Mar 10, 2025

Cross-site (XSS) vulnerability with Express API in Eta

CVE-2023-23630

Description

Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to res.render.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
etanpm
< 2.0.02.0.0

Affected products

2
  • ghsa-coords
    Range: < 2.0.0
  • eta-dev/etav5
    Range: < 2.0.0

Patches

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

5

News mentions

0

No linked articles in our index yet.