CVE-2022-25967 HIGH

CVE-2022-25967

Vendor N/A
Product eta
Weakness CWE-94 · Code injection
Published January 30, 2023
Last update March 27, 2025

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P

What the vulnerability does

01Description

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

Key dates

02Disclosure timeline

January 30, 2023 CVE published
March 27, 2025 Record updated