{"id":"CVE-2024-45390","aliases":["GHSA-q765-wm9j-66qj"],"url":"https://o3.security/vulnerability/CVE-2024-45390","summary":"@blakeembrey/template vulnerable to code injection when attacker controls template input","details":"### Impact\n\nIt is possible to inject and run code within the template if the attacker has access to write the template name.\n\n```js\nconst { template } = require('@blakeembrey/template');\n\ntemplate(\"Hello {{name}}!\", \"exploit() {} && ((()=>{ console.log('success'); })()) && function pwned\");\n```\n\n### Patches\n\nUpgrade to 1.2.0.\n\n### Workarounds\n\nDon't pass untrusted input as the template display name, or don't use the display name feature.\n\n### References\n\nFixed by removing in https://github.com/blakeembrey/js-template/commit/b8d9aa999e464816c6cfb14acd1ad0f5d1e335aa.","published":"2024-09-03T19:37:31.763Z","modified":"2026-08-12T03:51:35.849125343Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@blakeembrey/template","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/blakeembrey/js-template/commit/b8d9aa999e464816c6cfb14acd1ad0f5d1e335aa","label":"blakeembrey/js-template@b8d9aa9"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45390.json"},{"type":"ADVISORY","url":"https://github.com/blakeembrey/js-template/security/advisories/GHSA-q765-wm9j-66qj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45390"},{"type":"FIX","url":"https://github.com/blakeembrey/js-template/commit/b8d9aa999e464816c6cfb14acd1ad0f5d1e335aa"},{"type":"PACKAGE","url":"https://github.com/blakeembrey/js-template"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:35.849125343Z"}}