PT-2026-34725 · Pypi+3 · Mako+3

·

CVE-2026-41205

·

Published

2026-04-16

·

Updated

2026-07-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mako versions prior to 1.3.11
Description Mako is a template library written in Python. The get template() function within TemplateLookup is susceptible to path traversal when a URI begins with //. This occurs due to an inconsistency between two slash-stripping implementations. If an application passes untrusted input directly to get template(), any file readable by the process can be returned as rendered template content.
Recommendations Update to version 1.3.11.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83606
BDU:2026-10804
CLEANSTART-2026-AN24336
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-FT24360
CLEANSTART-2026-FU07345
CLEANSTART-2026-JU43269
CLEANSTART-2026-KE11953
CLEANSTART-2026-LJ72726
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-UO85049
CVE-2026-41205
ECHO-0E1E-5A56-ED2D
GHSA-V92G-XGXW-VVMM
OPENSUSE-SU-2026:10616-1
OPENSUSE-SU-2026:20645-1
PYSEC-2026-88
SUSE-SU-2026:1819-1
SUSE-SU-2026:1820-1
SUSE-SU-2026:21426-1
USN-8234-1

Affected Products

Linuxmint
Mako
Red Os
Ubuntu