mde / ejs

Embedded JavaScript templates -- http://ejs.co
Apache License 2.0
7.74k stars 843 forks source link

High CVE for latest version of ejs@3.1.9 #727

Closed sonu-jmh closed 1 year ago

sonu-jmh commented 1 year ago

There is a high severity CVE reported by Mend(Whitesource) ejs@3.1.9. NPM showing 3.1.9 as the latest available version. Is there any update when the fix is planned to be released?

RyanZim commented 1 year ago

Duplicate of https://github.com/mde/ejs/issues/720#issuecomment-1540435858