VYPR

Nunjucks

by Mozilla Corporation

CVEs (1)

  • CVE-2023-2142Nov 26, 2024
    risk 0.00cvss epss 0.00

    In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads…