PT-2026-64033 · Tugtainer · Tugtainer
CVE-2026-47752
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tugtainer versions prior to 1.30.2
Description
The notification template feature allows authenticated users to perform Server-Side Template Injection (SSTI), a flaw where an attacker injects malicious code into a template that is then executed on the server. The
title template and body template fields are processed using an unsandboxed jinja2.Environment, which enables the execution of arbitrary OS commands with root privileges inside the container.Recommendations
Update to version 1.30.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tugtainer