A cross-site scripting vulnerability was found in nodejs-ejs < 2.5.5 that allows the attacker under certain conditions control and override the filename option causing it to render the value as is, without escaping it. Upstream patch: https://github.com/mde/ejs/commit/49264e0037e313a0a3e033450b5c184112516d8f External Reference: https://snyk.io/vuln/npm:ejs:20161130
Created nodejs-ejs tracking bugs for this issue: Affects: fedora-all [bug 1404189] Affects: epel-all [bug 1404190]