Logo
vulnerabilityCVE-2026-41205
Name
CVE-2026-41205
Source
NVD ( link)Debian ( link)
Description
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
python-mako
Exploitable

Vulnerability Ratings#


7.7
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.8
Exploitable
buildroot
master
1.3.12
Not Affected
openwrt
master
1.3.12-r1
Not Affected