StackRadar

CVE-2021-21353

Medium

Advisory

Published 3 Mar 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.043
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
2 of 2
affected packages

Remote code execution via the `pretty` option.

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
pugnpm1.0.0, 1.39.1-prel, 2.0.3, 2.0.4+1 more3.0.19
pug-code-gennpm2.0.1, 3.0.12.0.3, 3.0.22
OSV records
GHSA-p493-635q-r6gr

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
pug@1.0.0
3.0.1

Open the chart page →

4,577
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
pug@1.0.0
3.0.1

Open the chart page →

8,212
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
pug@1.0.0
3.0.1

Open the chart page →

31,844
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pug@1.0.0
3.0.1

Open the chart page →

14,559
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
pug@1.39.1-prel
3.0.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
pug@1.39.1-prel
3.0.1

Open the chart page →

24,319
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
pug@2.0.3
pug-code-gen@2.0.1
3.0.1
2.0.3

Open the chart page →

7,929
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
pug@3.0.0
pug-code-gen@3.0.1
3.0.1
3.0.2

Open the chart page →

6,684
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2021-21353.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
pug@2.0.4
3.0.1
socialmediamacroscope/smile_server:0.3.31a528c794270
pug@2.0.3
3.0.1

Open the chart page →

109,294

Container images carrying it

9 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
governify/assets-manager:v1.4.12987672448c7
pug@1.39.1-prel
3.0.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
pug@2.0.3
pug-code-gen@2.0.1
3.0.1
2.0.3
1
codercom/code-server:4.11.0-debian1e2cc688008e
pug@1.0.0
3.0.1
1
codercom/code-server:3.10.247605610ad8d
pug@1.0.0
3.0.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
pug@1.0.0
3.0.1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
pug@3.0.0
pug-code-gen@3.0.1
3.0.1
3.0.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
pug@2.0.4
3.0.1
1
socialmediamacroscope/smile_server:0.3.31a528c794270
pug@2.0.3
3.0.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pug@1.0.0
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.