Teddy is a readable and easy to learn templating language. This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).
{ "nvd_published_at": "2021-10-07T17:15:00Z", "github_reviewed_at": "2021-10-08T21:52:26Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-79", "CWE-843" ] }