Tag
cve-2022-29078
Safeguard articles tagged "cve-2022-29078" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Open Source
Using EJS on npm Safely: CVE-2022-29078 and Beyond
The ejs npm package is a capable template engine that has also been the subject of a serious RCE advisory. Here is how to use it without opening that door.
Mar 29, 20265 min read
Vulnerability Analysis
EJS template engine RCE via client option (CVE-2022-29078)
CVE-2022-29078 lets attackers achieve remote code execution in EJS via unsanitized render options. Affected versions, severity, and fixes inside.
Jan 5, 20267 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.