PT-2026-97497 · Jinja · Jinja
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The product name cannot be determined (affected versions not specified)
Description
The notification template Jinja AST whitelist only inspects static Getattr nodes. This allows dynamic subscripts, such as
job['job'+' env'], and conditional gating, such as {% if job.id > 100 %}, to bypass both the AST check and the test-render process. At runtime, the gated branch executes and exceptions write full tracebacks into the notification body, which is then POSTed to an attacker-controlled webhook URL. This process leaks sensitive information, including install paths, Python version, and source line numbers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jinja