Vulnerability record · CVE-2021-32819 · published 14 May 2021
CVE-2021-32819: Squirrelly template engine config overwrite leads to RCE
Squirrelly · Squirrelly
Squirrelly, a JavaScript template engine used with ExpressJS, mixes pure template data with engine configuration options through the Express render API. An attacker who can supply template data can overwrite internal configuration options, which can trigger remote code execution in downstream applications. The flaw is fixed in version 9.0.0.
Description
Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS and a public exploit advisory, though exploitation requires user interaction and no KEV listing.
What it is
Squirrelly, a JavaScript template engine used with ExpressJS, mixes pure template data with engine configuration options through the Express render API. An attacker who can supply template data can overwrite internal configuration options, which can trigger remote code execution in downstream applications. The flaw is fixed in version 9.0.0.
Impact
An attacker gains remote code execution in the context of the affected Node.js application, allowing arbitrary code execution, data theft, or full host compromise.
Attack surface
Reached over the network through the Express render API when untrusted template data is passed into Squirrelly; the CVSS vector indicates no privileges are required but user interaction is required (UI:R).
Exploitation
Not listed in CISA KEV, but EPSS is high (0.583, 99th percentile) and the GitHub Security Lab advisory is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Squirrelly to version 9.0.0 or later.
- Do not pass untrusted user input as template data or configuration to the Express render API.
- Sanitize or strictly validate any data reaching template rendering paths.
- Isolate Node.js services that render templates with least privilege and network restrictions.
Detection
- Monitor application logs for unexpected template rendering errors or configuration changes.
- Audit code paths where user input reaches Squirrelly render calls.
- Watch for anomalous child process or shell execution spawned by Node.js processes.
- Track dependency versions to confirm Squirrelly is at or above 9.0.0.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-32819 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32819), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.