ejs
127 known vulnerabilities · 4 critical · 6 high
ejs is vulnerable to remote code execution due to weak input validation
@sveltejs/adapter-node has a BODY_SIZE_LIMIT bypass
Sveltejs devalue's `devalue.parse` and `devalue.unflatten` emit objects with `__proto__` own properties
Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate
@sveltejs/kit: Unvalidated redirect in handle hook causes Denial-of-Service
Malicious code in @ensdomains/dnsprovejs (npm)
Malicious code in courier-plugin-sdk-nodejs (npm)
Malicious code in checkpackagejson (npm)
Malicious code in metadata-api-nodejs (npm)
Malicious code in facebook-nodejs-business-sdk-tests (npm)
Malicious code in audit-ejs (npm)
Malicious code in nodejs-docs-samples-iot-mqtt-example (npm)
Malicious code in nodejs-driver (npm)
AWS Advanced NodeJS Wrapper: Privilege Escalation in Aurora PostgreSQL instance
Malicious code in textlint-checker-for-vuejs-jp-docs (npm)
Malicious code in @asyncapi/nodejs-template (npm)
Malicious code in @asyncapi/nodejs-ws-template (npm)
Malicious code in samplenodejsservice (npm)
Malicious code in cktool.target.nodejs (npm)
Malicious code in dynatrace-oneagent-nodejs (npm)
@vitejs/plugin-rsc has a Denial of Service with React Server Components
Malicious code in knn-kdtreejs (npm)
Malicious code in babelhelspevvuejsxmergeprops (npm)
Malicious code in ee-server-auth-nodejs (npm)
Malicious code in nodejs-encrypt-agent (npm)
Nodejs ‘undici’ vulnerable to CRLF Injection via Content-Type
Malicious code in paytm-mini-programs-nodejs-sdk (npm)
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
Malicious code in webpack-compilejsx (npm)
Malicious code in spire.officejs-document (npm)
Malicious code in redox-sample-nodejs (npm)
Malicious code in dotenv-nodejs (npm)
Malicious code in spire.officejs-fonts (npm)
Malicious code in @localizejs/fetlife-assets (npm)
Malicious code in nodejs-fetch-proxy (npm)
Malicious code in nodejs-gcloud-pubsub-module (npm)
Malicious code in simplejsonform (npm)
Apache SkyWalking NodeJS Agent can lose availability if header includes illegal SkyWalking header
Malicious code in nodejs-email (npm)
Malicious code in preloadsmartablejs (npm)
Malicious code in testherejson (npm)
Malicious code in rapyd-nodejs (npm)
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Malicious code in @dungnt11/splidejs (npm)
Malicious code in quest-bee-nodejs (npm)
Malicious code in slint-config-nodejs (npm)
Malicious code in poppejs (npm)
Malicious code in vimeo-threejs-player (npm)
Malicious code in zohocrm-nodejs-sdk-3.0 (npm)
Malicious code in grenache-nodejs-fib-client (npm)
Malicious code in wallet-nodejs-binding (npm)
Malicious code in google-auth-library-nodejs (npm)
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Malicious code in spire.officejs-externs (npm)
Malicious code in nodejs-socket (npm)
Malicious code in @ensdomains/dnssecoraclejs (npm)
Malicious code in xbcrypt-nohejs (npm)
Malicious code in logbin-nodejs (npm)
Malicious code in angara.tablejs (npm)
Malicious code in @productdevbook/animejs-vue (npm)
Malicious code in capacitybot-cf-nodejs-fct (npm)
Malicious code in invision-nodejs-test-utils (npm)
Malicious code in chart-tablejs (npm)
Malicious code in ejs-audit (npm)
Malicious code in euirejs (npm)
Malicious code in next2ejs (npm)
Malicious code in generic-synthetic-nodejs (npm)
Malicious code in meetingsdk-sample-vuejs (npm)
Malicious code in myjohndeereapi-oauth2-nodejs-example (npm)
Malicious code in nodejs-cookie-proxy-agent (npm)
Malicious code in example-nodejs-express (npm)
Malicious code in react-vuejs (npm)
Malicious code in grenache-nodejs-example-fib-client (npm)
Malicious code in grenache-nodejs-example-fib-server (npm)
Malicious code in grenache-nodejs-fib-server (npm)
Malicious code in grenache-nodejs-utp (npm)
Malicious code in nodejs-color (npm)
Malicious code in spire.officejs-common (npm)
Malicious code in output-scrubber-nodejs (npm)
Malicious code in gwnodejssectest1 (npm)
Malicious code in auth0-nodejs-webapp-sample-new-test (npm)
Malicious code in vue2ejs (npm)
Malicious code in webhooks-resources-nodejs-server (npm)
Malicious code in finastra-nodejs-libs (npm)
Malicious code in aps-simple-viewer-nodejs (npm)
Malicious code in ironfish-rust-nodejs (npm)
Malicious code in lbank-connector-nodejs (npm)
Malicious code in config-sdk-nodejs (npm)
Malicious code in resume-sourcing-nodejs-client-credentials (npm)
Malicious code in nodejs-prom-reporter (npm)
Malicious code in sample-nodejs-vsk-with-adm (npm)
Malicious code in remote-pay-cloud-nodejs-example (npm)
Malicious code in requirejs-injector (npm)
Malicious code in eslint-config-sunset-nodejs (npm)
Malicious code in cdp-agentkit-nodejs (npm)
Malicious code in zoomapps-texteditor-vuejs (npm)
Malicious code in pushservicejs (npm)
Malicious code in organizer-nodejs (npm)
Malicious code in nodejs-docs-samples-vision (npm)
Malicious code in nodejs-website (npm)
Malicious code in wetimejs-twilio-internal (npm)
Malicious code in wasabi-nodejs (npm)
@sveltejs/kit has memory amplification DoS vulnerability in Remote Functions binary form deserializer (application/x-sveltekit-formdata)
Malicious code in fe-core-components-vuejs (npm)
Malicious code in luhrfzvejsgcakmb (npm)
Malicious code in paytm-kapacitor-simplejson-datasource (npm)
Malicious code in env-nodejs (npm)
Malicious code in aws-crt-nodejs (npm)
Malicious code in polyfill-corejs2 (npm)
Malicious code in parsejson-pro (npm)
Malicious code in spire.officejs-editors (npm)