Executive brief
Pug, a popular template engine for Node.js, is vulnerable to a security flaw that could allow an attacker to execute malicious code. This occurs when an application incorrectly passes untrusted user input into specific template compilation settings. If exploited, this could lead to a full system compromise or unauthorized access to sensitive data.
Technical details
A code injection vulnerability exists in Pug (formerly Jade) through version 3.0.2. The vulnerability is rooted in the 'pug-code-gen' package, where the 'name' and 'globals' options in functions such as compileClient, compileFileClient, and compileClientWithDependenciesTracked are not properly sanitized. If an attacker can control these options, they can inject arbitrary JavaScript code into the generated template function. While these functions are typically used for internal template compilation, any application exposing these options to user-controlled input is at risk of Remote Code Execution (RCE). The fix, introduced in version 3.0.3, implements regex validation to ensure these options are valid JavaScript identifiers.
Affected products
- pugjs pug-code-gen <= 3.0.2
- pugjs pug <= 3.0.2
Timeline
- 2024-05-24: patched: Version 3.0.3 released to address the vulnerability.
- 2024-05-24: disclosed: Advisory published via GitHub and NVD.
References
- https://github.com/pugjs/pug/pull/3428
- https://github.com/pugjs/pug/pull/3438
- https://github.com/pugjs/pug/commit/32acfe8f197dc44c54e8af32c7d7b19aa9d350fb
- https://github.com/Coding-Competition-Team/hackac-2024/tree/main/web/pug
- https://github.com/pugjs/pug
- https://github.com/pugjs/pug/blob/4767cafea0af3d3f935553df0f9a8a6e76d470c2/packages/pug/lib/index.js