Executive brief
squirrelly is a JavaScript templating engine used in Node.js applications to dynamically render HTML and text. A code injection vulnerability in version 9.0.0 allows attackers to inject and execute arbitrary JavaScript code by manipulating the options.varName parameter, potentially compromising the entire application and its data.
Technical details
The vulnerability is a code injection flaw (CWE-94) in squirrelly v9.0.0 stemming from insufficient validation of the options.varName parameter. When constructing template code, the library fails to validate that varName is a valid JavaScript identifier, allowing an attacker to inject arbitrary code through this parameter. The attack requires no authentication and is reachable over the network if the application exposes templating functionality. An attacker can achieve remote code execution within the context of the Node.js application. The vulnerability was fixed in version 9.1.0 by adding validation to ensure options.varName conforms to valid JavaScript identifier syntax.
Affected products
- squirrelly squirrelly 9.0.0
Timeline
- 2024-08-21: disclosed
- 2024-09-02: patched: Fixed in version 9.1.0 (merged July 2, 2024)