CVE-2026-71215
EUVD-2026-5321205.08.2026, 08:16
art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include and extend template directives, resolves the target file path via path.resolve(root, filename) with no check afterward that the result remains inside root.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References