CVE-2022-25967: Eta.js Eta

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.

Affected products

  • Eta.js Eta: before 2.0.0 (fixed in 2.0.0)

Published 2023-01-30. Last modified 2026-06-17.