CRITICAL 9.8 NuGet

Code injection in RazorEngine

GHSA-ph3v-2hq5-5qfq · CVE-2021-46703

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Ready to move

Start Securing

Free, no credit card | First findings in minutes