CVE-2022-29078 is a server-side template injection vulnerability in the Node.js Embedded JavaScript templates (EJS) package version 3.1.6. Attacker-controlled data supplied through the nested settings[view options][outputFunctionName] setting is parsed as an internal option and overwrites EJS's outputFunctionName option. A malicious value can contain an operating-system command that is executed when the affected template is compiled.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a small Node.js/Express proof-of-concept application that intentionally demonstrates CVE-2022-29078 in EJS. The core vulnerable logic is in index.js: the GET / handler merges req.query directly into the object passed to res.render('page', data, ...). Because EJS accepts nested settings['view options'] and historically wrote outputFunctionName unsafely into generated template code, an attacker can supply a crafted query parameter to inject arbitrary JavaScript during template compilation. The included exploit payload uses outputFunctionName injection to execute setTimeout(function(){process.exit(1)},3000), proving remote code execution by crashing the Node.js server shortly after the response is sent. Repository structure is simple: index.js is the main application entry point; views/page.ejs and views/hello.ejs are the EJS templates; package.json defines dependencies including vulnerable ejs ^2.7.0 and start script; README.md explains the vulnerability, exploit flow, and remediation; .github/workflows/build-and-run.yml and seal-security.yml automate launching the vulnerable and remediated app via ngrok; Jenkinsfile shows equivalent CI remediation with Seal. This is not a generic exploit toolkit but an intentionally vulnerable demo app plus CI examples showing how Seal Security remediates the dependency. Main exploit capability: unauthenticated web-based SSTI/RCE against the root route using query-string injection. The exploit is operational rather than just theoretical because the repository includes a working vulnerable app, a concrete exploit URL, and logic that visibly confirms successful code execution. Notable observables include the local listener on port 3001, the vulnerable route /, the published ngrok URL used in CI, and several external hosts for ngrok, Seal, GitHub, and jsDelivr. A notable security issue beyond the demo itself is that both GitHub workflow files contain a hardcoded ngrok authtoken, which is a sensitive credential exposure.
This repository is a self-contained Dockerized proof-of-concept lab for CVE-2022-29078, an EJS server-side template injection leading to remote code execution. The structure is simple and purposeful: app/server.js contains a minimal Express application, app/views/page.ejs is the rendered template, app/package.json pins vulnerable dependencies (notably ejs 3.1.6), Dockerfile and docker-compose.yml build and expose the lab environment, and poc.sh performs the exploit. The core vulnerability is in the /page route, where req.query is passed directly into res.render('page', req.query). Because EJS versions prior to 3.1.7 do not safely validate outputFunctionName, an attacker can supply a nested query parameter such as settings[view options][outputFunctionName] and inject JavaScript into the generated template function. The included payload uses process.mainModule.require('child_process').execSync() to run shell commands. The PoC is operational rather than merely demonstrative: it sends crafted HTTP requests to the vulnerable endpoint, executes commands in the containerized Node process, writes output to /tmp/out, and retrieves that output with docker compose exec. Demonstrated capabilities include privilege/context discovery via id, arbitrary file read via cat /etc/passwd, and environment disclosure via uname -a. The repository is not part of a larger exploit framework; it is a standalone educational exploit lab showing both exploitation and mitigations.
This repository is a small Node.js/Express demo app intentionally exposing EJS template rendering in an unsafe way to demonstrate CVE-2022-29078 (EJS 2.7.4 server-side template injection leading to RCE). Repository structure and purpose: - index.js: Express server on port 3001 with a single GET / route. It calls res.render('page', req.query, cb). Passing req.query directly allows attacker-controlled parameters to reach EJS render options (notably settings['view options']['outputFunctionName']). Error handling returns a friendly "Invalid parameter" message when outputFunctionName-related errors occur. - views/page.ejs and views/hello.ejs: Simple EJS templates that display "Hello <name>!". - package.json: Declares dependencies including ejs ^2.7.0 (vulnerable range), plus other unrelated packages. - .github/workflows/build_and_run.yml: CI workflow that installs dependencies, starts the app, and exposes it via ngrok at https://sealtest.ngrok.dev. It prints both a normal URL and a crafted exploit URL that injects JavaScript into outputFunctionName to execute child_process.execSync('killall node'). - .github/workflows/seal-security.yml: Similar workflow but runs Seal Security remediation (seal-community/cli-action) to patch dependencies in-place (backporting sanitization to an EJS 2.7.4-sp1 style build), then re-runs the app and re-tests the same exploit. Exploit capability: - Remote, unauthenticated RCE primitive via HTTP query parameters by abusing EJS's unsanitized outputFunctionName option (CVE-2022-29078). The included payload demonstrates command execution by killing the Node process (DoS), but the same primitive could run arbitrary commands (reverse shell, file access, etc.).
This repository contains a proof-of-concept exploit for CVE-2022-29078, a vulnerability in ejs version 3.1.6. The exploit is implemented in a single Python script (CVE-2022-29078.py) that takes a target URL as an argument. It repeatedly prompts the user for system commands, which are then injected into a specially crafted POST request to the target URL. The payload leverages Node.js's 'child_process.execSync' to execute arbitrary commands on the server. The exploit is interactive, providing a shell-like experience to the attacker. The README.md provides usage instructions and an example. The main attack vector is network-based, targeting a vulnerable HTTP endpoint. No hardcoded IPs or domains are present; the target is specified at runtime.
This repository provides a working exploit for CVE-2022-29078, a server-side template injection (SSTI) vulnerability in the ejs (Embedded JavaScript templates) package for Node.js (version 3.1.6). The exploit is implemented in a single Python script (CVE-2022-29078.py), which sends a crafted POST request to a user-specified target URL. The request injects a malicious value into the settings[view options][outputFunctionName] parameter, causing the server to execute arbitrary OS commands. By default, the payload opens a reverse shell from the target server to the attacker's machine (IP 10.2.4.61, port 443). The script requires the attacker to provide the target URL, a username, and a password. The README.md provides background on the vulnerability, usage instructions, and references. The repository is focused and operational, containing only the exploit script, a README, and a .gitignore file.
This repository is a proof-of-concept (POC) exploit for CVE-2022-29078, targeting EJS version 3.1.6 in a Node.js Express application. The repository contains a Dockerfile to build and run a vulnerable web application, with the main logic in app.js. The application exposes several endpoints, with /page being vulnerable to server-side template injection (SSTI) due to unsanitized use of user-supplied query parameters in EJS rendering. The README provides clear instructions for setup and exploitation, including a sample payload that demonstrates remote code execution by creating a file on the server. The exploit leverages a crafted URL parameter to inject JavaScript code, exploiting the EJS template engine's outputFunctionName option. The repository structure is typical for a Node.js web app, with supporting EJS templates and Docker configuration files. The main exploit capability is remote code execution via network access to the /page endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An EJS template-injection vulnerability referenced as related background material; the content provides no further CVE-specific technical details.
Unknown; the content provides no vulnerability details.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.