← Back to browse · API

CVE-2021-32819

Severity
HIGH
CVSS
8.0
EPSS
0.59844
Risk score
52.95
CISA KEV
No
PoC
No
Published
2021-05-14
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-1163, GHSA-Q8J6-PWQX-PM96
Products
squirrellyjs:squirrelly 9.0.0 <9.0.0
Sources
euvd EUVD-2021-1163

Description

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

References