Executive brief
@blakeembrey/template is a JavaScript library for rendering string templates. A code injection vulnerability allows attackers who control the template display name parameter to execute arbitrary code in the application. This can lead to data theft, service disruption, or account compromise depending on the application's privileges.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the template display name functionality. When an attacker supplies malicious input to the template name parameter, they can inject and execute arbitrary JavaScript code. The attack requires network access and no authentication or user interaction. An attacker can achieve remote code execution within the context of the application using the library. The vulnerability is fixed in version 1.2.0 by removing the vulnerable display name feature; users should upgrade immediately or avoid passing untrusted input to the template name parameter.
Affected products
- Blake Embrey @blakeembrey/template <1.2.0
Timeline
- 2024-09-03: disclosed: Advisory published on GitHub Security Advisory
- 2024-09-03: patched: Fixed in version 1.2.0