Releases53
Frequency2 months 1 week
Last Release
Stars8.96K
A powerful templating engine with inheritance, asynchronous control, and more (jinja2 inspired)

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

4.3 MEDIUM

Nunjucks is a full featured templating engine for JavaScript. Versions 2.4.2 and lower have a cross site scripting (XSS) vulnerability in autoescape mode. In autoescape mode, all template vars should automatically be escaped. By using an array for the keys, such as `name[]=<script>alert(1)</script>`, it is possible to bypass autoescaping and inject content into the DOM.