Critical severity9.8NVD Advisory· Published May 4, 2023· Updated Jun 17, 2026
CVE-2023-29827
CVE-2023-29827
Description
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through the configuration settings of the closeDelimiter parameter. NOTE: this is disputed by the vendor because the render function is not intended to be used with untrusted input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/mde/ejs/issues/720nvdExploitIssue TrackingPatch
- github.com/mde/ejs/blob/main/SECURITY.mdnvdThird Party Advisory
News mentions
0No linked articles in our index yet.