Impact
A template author who writes a template in Go's standard html/template package may create a mis‑interpreted ‘yield’ keyword if it is not escaped. The flawed logic fails to neutralize input correctly, corresponding to CWE‑74, and allows the template engine to interpret untrusted text as a template command. This can lead to unintended template execution or injection of malicious content into rendered output, representing a potential template injection vulnerability.
Affected Systems
The vulnerability is present in the Go standard library package html/template. No specific version ranges are listed in the advisory, so users should verify whether their installed Go release incorporates the fix referenced in the official issue tracker. Any version prior to the patch that allows an unescaped ‘yield’ token in trusted author templates is affected.
Risk and Exploitability
The CVE does not provide a CVSS or EPSS score, and it is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector requires an attacker to control or modify a trusted template that contains an unescaped ‘yield’ keyword, which could happen when developers unknowingly deploy such templates or when templates are retrieved from untrusted sources. Because the flaw is limited to trusted template authors, the likelihood of exploitation depends on the organization’s template management practices.
OpenCVE Enrichment