CVE-2017-1000228: Ejs
Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.
nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function
Affected products
- Ejs Ejs: before 2.5.3 (fixed in 2.5.3)
Published 2017-11-17. Last modified 2026-06-17.