github / advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International
1.68k stars 312 forks source link

[GHSA-3965-hpx2-q597] Pug allows JavaScript code execution if an application accepts untrusted input #4467

Closed davidrunger closed 1 month ago

davidrunger commented 1 month ago

Updates

Comments Patched in this PR: https://github.com/pugjs/pug/pull/3438 which was released as pug 3.0.3 and pug-code-gen 3.0.3 as mentioned here https://github.com/pugjs/pug/releases/tag/pug%403.0.3 and as can be seen here https://diff.intrinsic.com/pug/3.0.2/3.0.3 and here https://diff.intrinsic.com/pug-code-gen/3.0.2/3.0.3

advisory-database[bot] commented 1 month ago

Hi @davidrunger! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!