VYPR
High severity7.5NVD Advisory· Published Aug 5, 2026· Updated Aug 26, 2026

CVE-2026-71215

CVE-2026-71215

Description

art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.