CVE-2017-1000228: Ejs

Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.

nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

Affected products

  • Ejs Ejs: before 2.5.3 (fixed in 2.5.3)

Published 2017-11-17. Last modified 2026-06-17.