HIGH

CVE-2021-32819

CVSS v3

8.8

HIGH

EPSS Score

88.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

Technical details

Published
5/14/2021

Frequently asked questions

What is CVE-2021-32819?

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

Is CVE-2021-32819 actively exploited?

Active exploitation of CVE-2021-32819 has not been confirmed. The EPSS score is 88.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-32819?

CVE-2021-32819 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2021-32819 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.