CVE-2022-29078
CRITICAL 9.8EPSS 32.8%
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option with an arbitrary OS command (which is executed upon template compilation).
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 32.81% chance of exploitation in the next 30 days, 98th percentile
- Nuclei
- critical · CWE-94
- Published
- 2022-04-25
- Updated
- 2024-08-03
Proof-of-concept exploits (30)
- https://eslam.io/posts/ejs-server-side-template-injection-rce/
- 0pensrcerer/JfrogAdvSec-demo0★ · 2024-05-02
- NketiahGodfred/EJS-ssti-exploit1★ · 2024-12-01
- TheTechSurgeon/JfrogAdvSec-demo0★ · 2024-05-02
- carmineacanfora/express-js-appbundle0★ · 2026-04-15
- carmineacanfora/express-js-appbundle-clone0★ · 2024-11-08
- christophl-jf/express-js-appbundle-clone0★ · 2025-01-23
- chuckdu21/CVE-2022-290780★ · 2025-01-07
- cmoyamoradas/express-js-appbundle0★ · 2024-10-10
- cx-benjamin-simpson/JfrogAdvSec-demo0★ · 2024-05-02
- dangducloc/CVE_2022_290781★ · 2025-12-31
- etingertal/express-js-appbundle0★ · 2024-11-03
- idirouhab/ejs-frog-demo0★ · 2024-06-13
- l0n3m4n/CVE-2022-290783★ · 2024-11-08
- liam-star-black-master/expluatation_CVE-2022-290780★ · 2023-07-26
- matFroggy/taskForceNpm0★ · 2024-12-17
- megupatil/express-js-appbundle-demo0★ · 2024-10-18
- miko550/CVE-2022-290788★ · 2022-09-07
- muldos/dsod-ejs-demo0★ · 2024-10-24
- muldos/ejs-frog-demo1★ · 2026-08-24
- muldos/vuln-express1★ · 2023-04-18
- roybensh/devsecops-days-emea0★ · 2023-11-08
- roybensh/roybs-nodejs-project0★ · 2024-09-22
- shurochka1396/expluatation_CVE-2022-290780★ · 2023-07-26
- vorbittencourt/demo0030★ · 2024-08-07
- yalinjob/ejs-demo-yalin0★ · 2026-08-10
- yalinjob/express-js-ya0★ · 2025-02-20
- yoitsmikeho/express-js-appbundle0★ · 2026-07-03
- seal-sec-demo-2/JavaScript-Example
- taka3636/CVE-2022-29078