CVE-2021-32819
Insecure template handling in Squirrelly
8.0
HIGH
CVSS 3.1
EPSS 89.6%
Description
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. Version 9.0.0 has a fix for this issue. For complete details refer to the referenced [GHSL-2021-023](https://securitylab.github.com/advisories/GHSL-2021-023-squirrelly/).
How to fix CVE-2021-32819
To remediate CVE-2021-32819, upgrade the affected package to a fixed version below.
- —upgrade to 9.0.0 or later
Is CVE-2021-32819 being exploited?
Likely — EPSS is 89.6%, placing CVE-2021-32819 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 9.0.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.0 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |