GHSA-p493-635q-r6gr
Dashboard / Vulnerabilities / GHSA-p493-635q-r6gr
Summary: Remote code execution via the `pretty` option.
Details: ### Impact If a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. ### Patches Upgrade to `[email protected]` or `[email protected]` or `[email protected]`, which correctly sanitise the parameter. ### Workarounds If there is no way for un-trusted input to be passed to pug as the `pretty` option, e.g. if you compile templates in advance before applying user input to them, you do not need to upgrade. ### References Original report: https://github.com/pugjs/pug/issues/3312 ### For more information If you believe you have found other vulnerabilities, please **DO NOT** open an issue. Instead, you can follow the instructions in our [Security Policy](https://github.com/pugjs/pug/blob/master/SECURITY.md)
References: https://github.com/pugjs/pug/security/advisories/GHSA-p493-635q-r6gr, https://nvd.nist.gov/vuln/detail/CVE-2021-21353, https://github.com/pugjs/pug/issues/3312, https://github.com/pugjs/pug/pull/3314, https://github.com/pugjs/pug/commit/991e78f7c4220b2f8da042877c6f0ef5a4683be0, https://github.com/pugjs/pug/releases/tag/pug%403.0.1, https://www.npmjs.com/package/pug, https://www.npmjs.com/package/pug-code-gen
Affected packages
Package
Name: pug
Purl: pkg:npm/pug
Affected ranges
Type: SEMVER
Events:
