Run a sample app
git clone https://github.com/visionmedia/express.git
cd express
npm install
node examples/ejs/index.js
Then try this
curl -v -k "http://localhost:3000/no5_such3_file7.pl?\"><script>alert(73541);</script>"
The server returns
Cannot GET /no5_such3_file7.pl?"><script>alert(73541);</script>
as text/plain, but yeah depending on the client i can see that being troublesome :)