GHSA-2mf3-mr2r-r4vf
### Overview `@rhinostone/swig` is a maintained fork of the abandoned `swig` template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The `{% include %}`, `{% extends %}`, and `{% import %}` tags resolve their target path through the filesystem loader without confining the result to the configured template root. A path that traverses upward (`../`) escapes the root and reads an arbitrary file from the host filesystem, whose contents are emitted into the rendered output. ### Attack scenario The dangerous case does **not** require the attacker to control template source — only template **data** (the `locals` passed at render time). An application that renders a trusted template whose include / extends path is variable-driven is exposed: ```js // application code — a configured filesystem loader with a basepath swig.renderFile('page.html', { partial: req.query.partial }); ``` ``` {# page.html — trusted template #} {% include partial %} ``` Setting `?partial=../../../../etc/passwd` makes the loader resolve and read that file, and its contents are rendered into the response. A literal in trusted source is equally affected: `{% include "../../../etc/passwd" %}`. ### Impact Arbitrary local file disclosure (confidentiality). An attacker able to influence an include / extends / import path — directly, or via untrusted `locals` — can read files outside the template directory: application configuration, credentials, source code, `/etc/passwd`, and so on. There is no integrity or availability impact. ### Affected & patched Every published version up to and including `2.7.0` is affected — `@rhinostone/swig`, and the shared `@rhinostone/swig-core` loader, hence `@rhinostone/swig-twig`, `@rhinostone/swig-jinja2`, and `@rhinostone/swig-django` as well. Fixed in **`2.7.1`**: the filesystem loader now rejects any `include` / `extends` / `import` path that resolves outside the configured `basepath` root, i
Properties
- ghsa_id
- GHSA-2mf3-mr2r-r4vf
- summary
- @rhinostone/swig: arbitrary local file read via include/extends path traversal
- severity
- high
- cvss_score
- 7.5
- cve_id
- GHSA-2mf3-mr2r-r4vf
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-08-18T16:31:16Z
- source_url
- https://github.com/advisories/GHSA-2mf3-mr2r-r4vf
- ghsa_updated
- 2026-08-18T16:31:19Z
Related Entities (12)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (5)
AFFECTS (5)
Explore deeper with Ninja Signal's threat intelligence graph