CVE-2021-23416 is a cross-site scripting (CWE-79) vulnerability affecting all versions of the curly-bracket-parser package, where improper sanitization of user input when used as a template library can lead to injection attacks. This vulnerability carries a CVSS score of 6.1 (Medium), indicating a low attack complexity and requiring user interaction, with potential impacts on confidentiality and integrity. While no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion has been observed, organizations using the affected package should still consider remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:curly-bracket-parser_project:curly-bracket-parser:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.