CVE Database · CVE-2017-1000228
CVSS v3.1
N/A
EPSS
6.33%
Published
Nov 17, 2017
Modified
May 12, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Weaknesses (CWE)
Affected Products (1)
References (4)