← Back to CVE List

CVE-2024-45390

Published: 2024-09-03T20:15Z
Last Modified: 2024-09-12T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt