The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Fix available through Seal Security. No upgrade required, protect your application instantly.