Vulnerabilities (CVE)

Filtered by vendor Pugjs
Filtered by product Pug-code-gen
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21353 1 Pugjs 2 Pug, Pug-code-gen 2025-05-27 6.8 MEDIUM 6.8 MEDIUM
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. This is fixed in version 3.0.1. This advisory applies to multiple pug packages including "pug", "pug-code-gen". pug-code-ge ...

Show More