Pugjs is a template engine for Node.js and JavaScript environments; its vulnerability exposure centers on the core Pug template processor and code-generation components, with the durable signal being injection-class weaknesses including code injection and improper neutralization of special elements in downstream output. These weakness patterns reflect the inherent risks of dynamic template compilation and code generation in a language-agnostic templating context. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pugjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21353CRITICAL Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e | Mar 3, 2021 | 9.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pugjs.
Media articles that mention a CVE ID that affects a product developed by Pugjs — matched by CVE ID, not by vendor name.