Skip to content

react-scripts 5 is using EJS as a dependency, which has "Server side template injection high CVE in ejs@3.1.9" #13180

@sonu-jmh

Description

@sonu-jmh
  • React-scripts 5 is using ejs@3.1.9 as inner dependency as described at the bottom.
  • Ejs@3.1.9 has a critical CVE with severity (9.8)
  • How the CVE is going to be solved when the react-scripts is being used?
  • Is there any alternative library present that can be used instead of ejs incase the fix for CVE is not available?
  • The author of ejs library is not acknowledging the cve and has warned to use the render method to avoid the vulnerability.

Dependency Path:
react-scripts-5.0.1.tgz -> workbox-webpack-plugin-6.5.4.tgz -> workbox-build-6.5.4.tgz ->rollup-plugin-off-main-thread-2.2.3.tgz -> ejs-3.1.9.tgz

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions