High severity7.5NVD Advisory· Published Mar 15, 2023· Updated Jun 17, 2026
CVE-2023-25345
CVE-2023-25345
Description
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
swig-templatesnpm | <= 2.0.4 | — |
swignpm | <= 1.4.2 | — |
Affected products
3- swig-templates/swig-templatesdescription
- ghsa-coords2 versions
<= 1.4.2+ 1 more
- (no CPE)range: <= 1.4.2
- (no CPE)range: <= 2.0.4
Patches
Vulnerability mechanics
References
3- github.com/node-swig/swig-templates/issues/88nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-2rq5-699j-x7p6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-25345ghsaADVISORY
News mentions
0No linked articles in our index yet.