lukeed/tempura

lukeed/tempura

Releases8
Frequency5 months 4 days
Last Release
Stars529
A light, crispy, and delicious template engine 🍤

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM4.3 MEDIUM

This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.