The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
PoC: JavaScript-Example
Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration
PoC: C-test-2
Dependabot security automerge test - ejs CVE-2022-29078
PoC: vuln-ejs-critical
npm repo with ejs CVE-2022-29078 (CVSS 9.8, EPSS 32%) for Dependabot automerge testing
PoC: npm-demo
Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation
PoC: npm-demo
Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation
PoC: CVE-2022-29078
PoC for CVE-2022-29078
PoC: CVE-2022-29078
Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"
PoC: CVE-2022-29078
vuln ejs 3.1.6 docker
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free