Releases39
Frequency2 months 3 weeks
Last Release
Logic-less {{mustache}} templates with JavaScript

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
>= 2.0.0, < 2.14.18.8 HIGH6.5 MEDIUM

Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.

< 2.2.14.3 MEDIUM

mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.