Junglewise Threat Intelligence

CVE-2021-32818: haml-coffee template engine configuration injection

CVE-2021-32818 · Severity: low · CVSS 3.1 · Published 2021-05-17

Vendors: npm.

Executive brief

haml-coffee is a JavaScript templating engine used by Express-based web applications. A vulnerability allows attackers who can control template data (e.g., via query parameters) to override the engine's configuration options, leading to remote code execution or bypassing of HTML escaping to enable reflected cross-site scripting attacks in downstream applications.

Technical details

The vulnerability stems from haml-coffee mixing template data with engine configuration options through the Express render API. Specifically, the engine allows configuration parameters like customHtmlEscape and escapeHtml to be controlled through the same object passed to res.render(). When a vulnerable application passes user-controlled data (e.g., req.query) directly to the template engine, an attacker can inject malicious configuration to override HTML helper functions (enabling RCE via arbitrary function execution) or disable HTML escaping (enabling reflected XSS). Attack vector is network-based with low privilege required (ability to send HTTP requests). No official patch exists as of the advisory publication date; the vulnerability affects all versions through 1.14.1.

Affected products

  • haml-coffee haml-coffee all versions through 1.14.1

Timeline

  • 2021-05-14: disclosed
  • 2021-05-17: advisory