CVE-2023-2142 - CVE House
Back to Database
Status published Unknown CVE-2023-2142

Nunjucks autoescape bypass leads to cross site scripting

Vulnerability Description

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2142

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • blaiddx64

Affected Vendor

Affected Software

Nunjucks
Vulnerable Versions:
0

Timeline

Official Publish: November 26th, 2024
Last Modified: November 27th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)