squirrelly
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting squirrellypage 1 of 1
- CVE-2021-32819HIGHCVSS 8.0EG 9.0✓ Fixed in 9.0.02021-05-14
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…
- CVE-2024-40453CRITICALCVSS 9.8EG 9.8✓ Fixed in 9.1.02024-08-21
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.
Check whether squirrelly is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for squirrelly CVEs against the assets you own.
Start Free Scan →