High severity7.5NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-71215
CVE-2026-71215
Description
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3(expand)+ 1 more
- (no CPE)
- (no CPE)
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.