PatchSiren cyber security CVE debrief
CVE-2015-8862 Mustache.js Project CVE debrief
CVE-2015-8862 describes a cross-site scripting issue in mustache for Node.js versions before 2.2.1. According to NVD, the weakness is CWE-79 and the attack requires user interaction because the unsafe output is triggered through a rendered template that includes an unquoted attribute. The practical defensive takeaway is straightforward: update mustache to 2.2.1 or later and review templates that render into HTML attributes, especially where input may be attacker-controlled.
- Vendor
- Mustache.js Project
- Product
- Mustache.js
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Teams running Node.js applications that use mustache to render HTML templates, especially if templates contain unquoted attributes or render untrusted values into markup.
Technical summary
The NVD record states that mustache package versions before 2.2.1 are vulnerable to XSS when a template contains an attribute that is not quoted. The mapped weakness is CWE-79. The NVD CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network-reachable impact with user interaction required and limited confidentiality/integrity effects.
Defensive priority
Medium. The issue is important for applications that generate browser-facing HTML from mustache templates, but mitigation is primarily an upgrade and template hygiene task rather than an emergency response.
Recommended defensive actions
- Upgrade mustache to version 2.2.1 or later everywhere it is used.
- Search templates for unquoted HTML attributes and convert them to quoted attributes.
- Review any rendering paths that place untrusted or partially trusted data into HTML output.
- Re-test pages and components that use mustache-rendered attributes after upgrading.
- Add dependency scanning or inventory checks so older mustache versions are flagged during builds and releases.
Evidence notes
The evidence corpus includes the NVD CVE record and linked references. NVD lists the vulnerable CPE range as mustache.js_project versions up to and including 2.2.0, with CWE-79 and the CVSS vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. NVD references a mailing-list advisory dated 2016-04-20, a Node Security advisory (62) marked as Exploit/Patch/Vendor Advisory, and a Tenable advisory, which support the product/version and remediation framing.
Sources and references
Verified primary and authoritative sources
-
CVE-2015-8862 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2015-8862
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2015-8862 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2015-8862
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://nodesecurity.io/advisories/62
[email protected] - Exploit, Patch, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://www.tenable.com/security/tns-2016-18
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.