GHSA-3965-hpx2-q597

    Dashboard / Vulnerabilities / GHSA-3965-hpx2-q597

    GHSA-3965-hpx2-q597

    Published: 24 May 2024Last Modified: 10 Sept 2026

    Summary: Pug allows JavaScript code execution if an application accepts untrusted input

    Details: Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the `compileClient`, `compileFileClient`, or `compileClientWithDependenciesTracked` function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.

    Affected packages

    Package

    Name: pug-code-gen

    Purl: pkg:npm/pug-code-gen

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.0.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3965-hpx2-q597 | CVE-DB