mirror of
https://github.com/CryptKeeperZK/ejs.git
synced 2026-01-08 15:13:50 -05:00
Update SECURITY.md
This commit is contained in:
@@ -18,3 +18,5 @@ To ensure the timely response to your report, please ensure that the entirety of
|
||||
|
||||
The EJS team will then evaluate your report and will reply with the next steps in handling your report and may ask for additional information or guidance.
|
||||
|
||||
## out of scope vulnerabilities
|
||||
If you give end-users unfettered access to the EJS render method, you are using EJS in an inherently un-secure way. Please do not report security issues that stem from doing that. EJS is effectively a JavaScript runtime. Its entire job is to execute JavaScript. If you run the EJS render method without checking the inputs yourself, you are responsible for the results.
|
||||
|
||||
Reference in New Issue
Block a user