VYPR

pug-code-gen

by Putty

CVEs (1)

  • CVE-2021-21353MedMar 3, 2021
    risk 0.38cvss 6.8epss 0.04

    Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug…