← Zurück zur CVE-Suche

CVE-2026-71286

Beschreibung

The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer-s compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input.

CVSS 6.1EPSS 0.155%Risiko 0.62
Quelle öffnen
Veröffentlicht
2026-08-05 13:24:53
Zuletzt geändert
2026-08-10 12:17:31
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N