$ filter --tag pug

1 post tagged #pug.

AST Injection through Pug
Web Security advanced

AST Injection through Pug

A detailed lab note on turning Prototype Pollution into code execution through Pug's AST/code-generation path: vulnerable merge, prototype chain behavior, debugger observations, exploit shape, trigger conditions and defenses.

2026-05-17