NA

CVE-2024-36361

Published: 24/05/2024 Updated: 06/06/2024

Vulnerability Summary

Pug up to and including 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.