S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-32819 Scanner

CVE-2021-32819 scanner - Remote Code Execution (RCE) vulnerability in squirrelly

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-32819
8.8
CVSShigh
Exploitable remotely over the internet · no authentication required · user interaction needed.

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
squirrellyby squirrellyjs
AFFECTED< 9.0.0SAFE ✓≥ 9.0.0
Updated Aug 21, 2026View on NVD →
Detail

Squirrelly is a powerful template engine whose primary use is in rendering templates for Node.js applications. It is implemented purely in JavaScript and works seamlessly alongside ExpressJS. Squirrelly offers an efficient way to keep data and template configuration options separate while still delivering the desired output. One of its advantages is its support for numerous syntax flavors, which allows developers to use a markup language that they are most comfortable with.

Recently, a security vulnerability (CVE-2021-32819) was detected in v8.2.2 and prior versions of Squirrelly. This vulnerability results from a failure in the engine's input validation. By tampering with internal configuration options, an attacker can easily smuggle malicious JavaScript code into the downstream application and exploit it to execute remote code. The vulnerability is particularly severe, as it can allow an attacker to steal or manipulate sensitive information or take control of the underlying system.

If left unrepaired, the CVE-2021-32819 vulnerability can lead to devastating consequences. Attackers can exploit this vulnerability in a variety of ways, including stealing sensitive data, corrupting systems, executing malicious code, and gaining unauthorized access to an application's resources. With this vulnerability, applications using Squirrelly templates are particularly exposed, and attackers can easily exploit their weakness to launch cyberattacks.

At S4E, we offer a powerful and comprehensive platform designed to ease your vulnerability management concerns. Our Pro-features let you monitor and track vulnerabilities in your digital assets while offering tips and solutions on how to mitigate them promptly. Thus, by using our platform, you can always be sure that you are using the latest cybersecurity best practices to keep your digital assets secure and protected.

 

REFERENCES

Solution Advice

To mitigate the vulnerability, developers must take certain precautions while working with Squirrelly. Below is a list of recommended best practices: 

  • Update to the latest version of Squirrelly (9.0.0) where this issue is fixed;
  • Use a secure template engine that has undergone proper security testing;
  • Conduct proper threat modeling of the application and evaluate the risks involved;
  • Use input validation to prevent malicious or unanticipated input from gaining access to the system;
  • Implement a robust security mechanism in the downstream application to monitor and block suspicious activities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.