Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 NuGet

Code injection in RazorEngine

GHSA-ph3v-2hq5-5qfq · CVE-2021-46703

Published · Modified

Description

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Ready to move

Start Securing

Free, no credit card | First findings in minutes