Medium severity6.1OSV Advisory· Published Aug 5, 2026· Updated Aug 26, 2026
CVE-2026-71286
CVE-2026-71286
Description
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2v0.0.6, v0.0.5, v0.0.4, …+ 1 more
- (no CPE)range: v0.0.6, v0.0.5, v0.0.4, …
- (no CPE)
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.