-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from incomplete HTML escaping in Nunjucks' autoescape mechanism. The commit diff shows:
This indicates the core vulnerability was in the escaping logic handled by lib.js's escape mechanisms. The autoescape feature relied on these patterns to neutralize special characters, and the absence of backslash handling allowed XSS bypass when combined with multiple user-controlled parameters in template interpolation.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| nunjucks | npm | < 3.2.4 | 3.2.4 |
Ongoing coverage of React2Shell