CVE-2022-29078 describes a critical server-side template injection vulnerability in the ejs (Embedded JavaScript templates) package for Node.js, specifically version 3.1.6. This flaw allows an attacker to inject arbitrary OS commands via the settings[view options][outputFunctionName] parameter, which are then executed during template compilation. With a CVSS score of 9.8 (Critical), this vulnerability has a high potential for complete compromise of confidentiality, integrity, and availability, requiring no user interaction or authentication. While not listed in CISA's KEV catalog, a Nuclei template exists for detection, and community discussion indicates awareness, suggesting a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.6CPE matchmatch criteria | cpe:2.3:a:ejs:ejs:3.1.6:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.