CVE-2026-71286
EUVD-2026-5337105.08.2026, 13:24
The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer's compileTemplate (from @ember/template-compilation) with no sanitization, allow-listing, or validation of the input.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.