Advisories for Npm/Pug package

2024
2021

Remote code execution via the `pretty` option.

If a remote attacker was able to control the pretty option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend.