Loading HuntDB...

GHSA-c9hr-fvm9-7c49

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.

Related CVEs

Key Information

GHSA ID
GHSA-c9hr-fvm9-7c49
Published
May 11, 2023 6:30 PM
Last Modified
December 13, 2024 3:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 18, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.