Lucene search

K
osvGoogleOSV:GHSA-CF4H-3JHX-XVHQ
HistoryMay 06, 2021 - 4:09 p.m.

Arbitrary Code Execution in underscore

2021-05-0616:09:43
Google
osv.dev
22

0.011 Low

EPSS

Percentile

84.4%

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Execution via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

CPENameOperatorVersion
underscorege1.3.2
underscorelt1.12.1

References