Embedded JavaScript templates vulnerable to pollution
CVE-2024-33883

Currently unrated

Key Information:

Vendor

ejs

Vendor
CVE Published:
28 April 2024

Badges

👾 Exploit Exists

What is CVE-2024-33883?

The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.