Loading vulnerability details...
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-13ADA |
| Severity | CRITICAL |
| CWE | CWE-94 |
| Confidence | 90% |
| Category | logic_flaw |
| Exploitability | likely |
| Package | express@latest (nodejs) |
| Location | lib/view.js:44-48 |
| Affected Functions | View |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
When a view name lacks an extension, the constructor derives the extension from the defaultEngine and then loads the corresponding module with require(mod).__express. The module name is taken directly from the extension (e.g., ".ejs" -> "ejs"). An attacker who can influence the view name or defaultEngine can cause the application to require an arbitrary module, potentially executing malicious code if such a module is present in node_modules.
The vulnerability was identified in the file lib/view.js at lines 44-48 within the express package (version latest). The following functions are directly affected: View. Any code path that invokes these functions inherits this vulnerability.
File: lib/view.js (lines 44-48)
var mod = this.ext.slice(1)
debug('require "%s"', mod)
var fn = require(mod).__express
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Control the view name or defaultEngine to set an extension that maps to a malicious module (e.g., "malicious"), causing require('malicious').__express to be executed during view initialization.
Remote code execution on the server, allowing full compromise.
Whitelist allowed template engine extensions and reject any others. Load engines from a trusted registry rather than arbitrary require based on user-controlled input.
Advisory: SGZ-2026-13ADA | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer.
| Property | Value |
|---|---|
| Advisory ID | SGZ-2026-13ADA |
| Severity | CRITICAL |
| CWE | CWE-94 |
| Confidence | 90% |
| Category | logic_flaw |
| Exploitability | likely |
| Package | express@latest (nodejs) |
| Location | lib/view.js:44-48 |
| Affected Functions | View |
| Attack Vector | NETWORK |
| Attack Complexity | LOW |
| Privileges Required | NONE |
| Discovered By | SafeGuard Zero-Day AI Discovery Engine |
When a view name lacks an extension, the constructor derives the extension from the defaultEngine and then loads the corresponding module with require(mod).__express. The module name is taken directly from the extension (e.g., ".ejs" -> "ejs"). An attacker who can influence the view name or defaultEngine can cause the application to require an arbitrary module, potentially executing malicious code if such a module is present in node_modules.
The vulnerability was identified in the file lib/view.js at lines 44-48 within the express package (version latest). The following functions are directly affected: View. Any code path that invokes these functions inherits this vulnerability.
File: lib/view.js (lines 44-48)
var mod = this.ext.slice(1)
debug('require "%s"', mod)
var fn = require(mod).__express
The code above demonstrates the vulnerable pattern. This code is executed at runtime and can be directly exploited by an attacker with the appropriate access level.
Control the view name or defaultEngine to set an extension that maps to a malicious module (e.g., "malicious"), causing require('malicious').__express to be executed during view initialization.
Remote code execution on the server, allowing full compromise.
Whitelist allowed template engine extensions and reject any others. Load engines from a trusted registry rather than arbitrary require based on user-controlled input.
Advisory: SGZ-2026-13ADA | Source: SafeGuard Zero-Day AI Discovery | Status: Candidate
This vulnerability was autonomously discovered by SafeGuard's AI-powered Zero-Day Discovery engine using TAOR (Think-Act-Observe-Repeat) agentic analysis on the package source code. It is not yet tracked in any public vulnerability database (CVE, NVD, GHSA, OSV). This finding should be triaged by a security engineer and, if confirmed, reported upstream to the package maintainer. This vulnerability involves weaknesses in
This critical vulnerability poses an immediate and severe threat to system security. Exploitation could lead to complete system compromise, data breach, or denial of service. Immediate action is required.
Isolate affected systems from untrusted networks until patching is complete
Implement enhanced monitoring for exploitation attempts and unusual behavior