CVE-2024-36361: Pugjs Pug
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compiling Pug templates into JavaScript, and there would typically be no reason to allow untrusted callers.
Affected products
- Pugjs Pug: from 0.0.2, up to and including 3.0.2
Published 2024-05-24. Last modified 2026-06-17.