haml-coffee@1.13.7 vulnerabilities

Haml templates where you can write inline CoffeeScript.

Direct Vulnerabilities

Known vulnerabilities in the haml-coffee package. This does not include vulnerabilities belonging to this package’s dependencies.

Cross-site Scripting (XSS)

haml-coffee is a Haml templates where you can write inline CoffeeScript. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). A vulnerable application that passes user controlled request objects to the haml-coffee template engine may introduce RCE vulnerabilities. Additionally control over the escapeHtml parameter through template configuration pollution ensures that haml-coffee would not sanitize template inputs that may result in reflected Cross Site Scripting attacks against downstream applications.

How to fix Cross-site Scripting (XSS)?

There is no fixed version for haml-coffee.