Skip to content

fix: update ejs to 3.1.7 to fix CVE-2022-29078 template injection#9

Open
kiloconnect-development[bot] wants to merge 1 commit into
mainfrom
security-remediation/ejs-ghsa-phwq-j96m-2c2q/38046872d4-1
Open

fix: update ejs to 3.1.7 to fix CVE-2022-29078 template injection#9
kiloconnect-development[bot] wants to merge 1 commit into
mainfrom
security-remediation/ejs-ghsa-phwq-j96m-2c2q/38046872d4-1

Conversation

@kiloconnect-development

Copy link
Copy Markdown

Summary

  • Bumps ejs from 3.1.6 to 3.1.7 to patch CVE-2022-29078 (GHSA-phwq-j96m-2c2q), a server-side template injection vulnerability.
  • Updates both package.json and package-lock.json to the patched version.
  • This is a patch-level update with no breaking changes.

Kilo Finding: http://localhost:3000/security-agent/findings?findingId=38046872-d429-4697-a10f-906a688a299e

Bumps ejs from 3.1.6 to 3.1.7 to patch server-side template injection
vulnerability (GHSA-phwq-j96m-2c2q).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants