CVE-2021-23369

Published
View on NVD ↗
CVSS v3
5.6
MEDIUM
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

The package handlebars before 4.7.7 are vulnerable to Remote Code Execution (RCE) when selecting certain compiling options to compile templates coming from an untrusted source.

Minimal templating on steroids.
GitHubGitHub
18.6K