Releases66
Frequency2 months 1 week
Last Release
Lightweight, fast, and powerful embedded JS template engine

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
< 2.0.08.6 HIGH

Eta is an embedded JS templating engine that works inside Node, Deno, and the browser. XSS attack - anyone using the Express API is impacted. The problem has been resolved. Users should upgrade to version 2.0.0. As a workaround, don't pass user supplied things directly to `res.render`.

< 2.0.08.1 HIGH

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.