Node.js Embedded JavaScript 3.1.6 is susceptible to server-side template injection via settings[view options][outputFunctionName], which is parsed as an internal option and overwrites the outputFunctionName option with an arbitrary OS command, which is then executed upon template compilation.
id: CVE-2022-29078
info:
name: Node.js Embedded JavaScript 3.1.6 - Template Injection
author: F
...