Junglewise Threat Intelligence

CVE-2022-25967: Eta template engine code injection via user-defined data

CVE-2022-25967 · Severity: low · CVSS 3.1 · Published 2023-01-30

Vendors: npm.

Executive brief

Eta is a popular templating engine used in web applications to generate dynamic content. Versions before 2.0.0 are vulnerable to remote code execution when rendering templates with user-controlled data through Express render options. An attacker who can influence template render parameters could inject and execute arbitrary code on the server.

Technical details

This vulnerability is a code injection flaw (CWE-94) in Eta's template rendering mechanism. The root cause is improper separation of configuration and user data: the engine incorrectly merges user-supplied view options from the Express render API into its internal configuration, allowing attackers to overwrite critical template engine configuration variables. An attacker with ability to control template render parameters (e.g., via Express request data) can inject code that is executed during template compilation. The vulnerability requires user-defined data to be rendered in templates. The fix was implemented in version 2.0.0, which properly segregates configuration from data.

Affected products

  • Eta Eta before 2.0.0

Timeline

  • 2023-01-30: disclosed
  • 2023-01-27: patched: Fixed in version 2.0.0

References

Related threats