Logo
vulnerabilityCVE-2026-44307
Name
CVE-2026-44307
Source
NVD ( link)Debian ( link)
Description
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
python-mako
Exploitable

Vulnerability Ratings#


8.7
CVSSv4
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.8
Exploitable
buildroot
master
1.3.12
Not Affected
openwrt
master
1.4.1-r1
Not Affected
yocto
master
1.4.1
Not Affected