Tag
cve-2022-29078
Safeguard articles tagged "cve-2022-29078" — guides, analysis, and best practices for software supply chain and application security.
2 articles
Vulnerability Analysis
EJS template engine RCE via client option (CVE-2022-29078)
CVE-2022-29078 lets attackers achieve remote code execution in EJS via unsanitized render options. Affected versions, severity, and fixes inside.
Jan 5, 20267 min read
Open Source
Using EJS on npm Safely: CVE-2022-29078 and Beyond
The ejs npm package is a capable template engine that has also been the subject of a serious RCE advisory. Here is how to use it without opening that door.
Feb 24, 20255 min read
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.