In Pug (npm) prior to 3.0.1, a remote attacker who can influence the pretty option passed to the Pug compiler can trigger remote code execution on the Node.js backend. This can occur when an application spreads user-controlled objects (e.g., HTTP query parameters) into the options/inputs used for template compilation, allowing untrusted data to reach the compiler option pretty. The issue affects multiple packages in the Pug ecosystem, including pug and pug-code-gen, and is addressed by sanitizing/handling of the pretty parameter in fixed releases.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
pretty option (or otherwise merged into compiler options) for Pug compilation. If feasible, compile templates ahead of time so that runtime user input cannot affect compilation options.Patch, then assume compromise.
pretty option: pug@3.0.1 (or later). For pug-code-gen, upgrade to 3.0.2 (or later) or the backported fix 2.0.3.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Proof-of-Concept (POC) exploit for CVE-2021-21353, a Remote Code Execution (RCE) vulnerability in the 'pug' template engine for Node.js (version 3.0.0) and 'pug-code-gen' (version 3.0.0). The repository contains a minimal Node.js Express application that renders user-supplied input via the 'pretty' query parameter into a Pug template, exposing the RCE vulnerability. The exploit is demonstrated by passing a specially crafted payload to the 'pretty' parameter, which results in arbitrary command execution on the server. The README provides example payloads that exfiltrate sensitive data (such as the output of 'id' or the contents of /etc/passwd') to a remote webhook. The repository includes Docker and docker-compose files for easy setup, and the main entry point is 'app/index.js'. The exploit is network-based, targeting the HTTP endpoint at port 3000. This POC is not weaponized but demonstrates the vulnerability and its impact clearly.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.