Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-29078

61
FAUCET Score

CVE-2022-29078 describes a critical server-side template injection vulnerability in the ejs (Embedded JavaScript templates) package for Node.js, specifically version 3.1.6. This flaw allows an attacker to inject arbitrary OS commands via the settings[view options][outputFunctionName] parameter, which are then executed during template compilation. With a CVSS score of 9.8 (Critical), this vulnerability has a high potential for complete compromise of confidentiality, integrity, and availability, requiring no user interaction or authentication. While not listed in CISA's KEV catalog, a Nuclei template exists for detection, and community discussion indicates awareness, suggesting a high likelihood of exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
3.1.6CPE matchmatch criteria
cpe:2.3:a:ejs:ejs:3.1.6:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
32.81%
Probability of exploitation in next 30 days
EPSS Percentile
98.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2022-29078 · Jul 19, 2022
This CVE's current EPSS score of 0.3281 is in the 95th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

npmpatch availablevia ghsa
Product: ejsFixed in: 3.1.7
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: ejs
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/search-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/kui-web-terminal-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/mcm-topology-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for ContainersFixed in: rhmtc/openshift-migration-ui-rhel8
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-header-rhel8
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatend of lifevia redhat_api
Product: Red Hat Data Grid 8Fixed in: ejs

Vendor Advisories (2)

npmGHSA-phwq-j96m-2c2qcritical

ejs template injection vulnerability

Apr 26, 2022
redhatCVE-2022-29078Important

ejs: server-side template injection in outputFunctionName

Apr 25, 2022

References

eslam.io / posts/ejs-server-side-template-injection-rce
ExploitPatchThird Party Advisory
github.com / mde/ejs/releases
Release NotesThird Party Advisory
security.netapp.com / advisory/ntap-20220804-0001
Third Party Advisory