Mustache remote code injection vulnerability
High severity
GitHub Reviewed
Published
Jan 27, 2022
to the GitHub Advisory Database
•
Updated Feb 7, 2024
Description
Published by the National Vulnerability Database
Jan 21, 2022
Reviewed
Jan 24, 2022
Published to the GitHub Advisory Database
Jan 27, 2022
Last updated
Feb 7, 2024
In Mustache.php v2.0.0 through v2.14.0, Sections tag can lead to arbitrary php code execution even if strict_callables is true when section value is controllable.
References