PatchSiren

art-template CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH art-template CVE published 2026-08-05

CVE-2026-71215

The art-template library has a vulnerability in its sub-template resolution logic, which allows an attacker to read arbitrary files on disk accessible by the Node process if external input influences sub-template names. This vulnerability is rated HIGH with a CVSS score of 7.5. Developers and administrators using art-template in their applications should be aware of this vulnerability and take necessary p [truncated]