Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Tmont Pug 安全漏洞
Vulnerability Description
Tmont Pug是 Tmont开源的一个应用软件。提供了优化html的方式。 Tmont Pug 3.0.2及之前版本存在安全漏洞,该漏洞源于存在不受信任的输入,允许执行任意JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A