VYPR

npm package

express-handlebars

pkg:npm/express-handlebars

Vulnerabilities (1)

  • CVE-2021-32820May 14, 2021
    affected < 5.3.1fixed 5.3.1

    Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilities in downstream applications