{"id":"GHSA-w3w8-37jv-2c58","summary":"Cross-Site Scripting in mustache","details":"Versions of `mustache` prior to 2.2.1 are affected by a cross-site scripting vulnerability when attributes in mustache templates are not quoted.\n\n\n\n### Example\nTemplate:\n```\u003ca href={{foo}}/\u003e```\n\nInput:\n```{ 'foo' : 'test.com onload=alert(1)'}```\n\nRendered result:\n```\u003ca href=test.com onload=alert(1)/\u003e```\n\n\n## Recommendation\n\nUpdate to version 2.2.1 or later.\nAlternatively, ensure that all attributes in hmustache templates are encapsulated with quotes.","aliases":["CVE-2015-8862"],"modified":"2023-11-01T04:46:23.224015Z","published":"2017-10-24T18:33:36Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:59:24Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-8862"},{"type":"WEB","url":"https://github.com/janl/mustache.js/commit/378bcca8a5cfe4058f294a3dbb78e8755e8e0da5"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w3w8-37jv-2c58"},{"type":"PACKAGE","url":"https://github.com/janl/mustache.js"},{"type":"WEB","url":"https://www.npmjs.com/advisories/62"},{"type":"WEB","url":"https://www.tenable.com/security/tns-2016-18"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2016/04/20/11"},{"type":"WEB","url":"http://www.securityfocus.com/bid/96436"}],"affected":[{"package":{"name":"mustache","ecosystem":"npm","purl":"pkg:npm/mustache"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-w3w8-37jv-2c58/GHSA-w3w8-37jv-2c58.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}