Skip to content

[GHSA-297x-8xj4-vcxv] Improper Control of Generation of Code in doT - #10190

Open
zezeafonso wants to merge 1 commit into
zezeafonso/advisory-improvement-10190from
zezeafonso-GHSA-297x-8xj4-vcxv
Open

zezeafonso wants to merge 1 commit into
zezeafonso/advisory-improvement-10190from
zezeafonso-GHSA-297x-8xj4-vcxv

Conversation

@zezeafonso

Copy link
Copy Markdown

Updates

  • Affected products
  • Description

Comments
The version currently listed as patched still reproduces the issue described in this advisory.
I have a proof of concept demonstrating the issue in 1.1.3, which I can provide upon request.
The package itself has in its security considerations https://github.com/olado/doT#:~:text=doT%20allows,injection "doT allows arbitrary JavaScript code in templates, making it one of the most flexible and powerful templating engines. It means that doT security model assumes that you only use trusted templates and you don't use any user input as any part of the template, as otherwise it can lead to code injection."
Please review the patched-version designation. All versions should be listed as affected.

@github-actions
github-actions Bot changed the base branch from main to zezeafonso/advisory-improvement-10190 October 6, 2026 11:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant