Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisBaja (2.7)0.27%—Palletsprojects JinjaAI23/9/202625/9/2026
—
AplazadaBaja (2.1)0.39%—Langgenius DifyAIPocoo Jinja2AI3/8/202612/8/2026
A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine.…
AplazadaBaja (2.1)0.47%—Jcharis Machine-learning-web-appsAIPocoo Jinja2AI11/3/202617/6/2026
A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such…
AnalizadaCrítica (9.8)1.0%—Hubspot Jinjava4/2/202617/6/2026
JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox…
AnalizadaCrítica (10)2.1%—Hubspot Jinjava17/9/202517/6/2026
jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary classes. This enables…
AplazadaAlta (8.5)20%—SkyvernAIPalletsprojects JinjaAI7/6/202517/6/2026
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code…
AplazadaMedia (4.8)0.23%—Sarrionandia TournatrackAIPalletsprojects JinjaAI19/4/202517/6/2026
A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py of the component Jinja2 Template Handler. The manipulation of the argument ID leads to injection. It is…
AplazadaMedia (4.8)0.23%—Thautwarm Vscode-dianaAIPalletsprojects JinjaAI19/4/202517/6/2026
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
ModificadaMedia (5.4)0.51%—Palletsprojects JinjaDebian Linux5/3/202517/6/2026
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a…
AplazadaAlta (7.8)0.34%—AptrsAIDjangoAIPalletsprojects JinjaAI23/12/202417/6/2026
APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically,…
ModificadaMedia (5.4)0.52%—Palletsprojects Jinja23/12/202417/6/2026
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template.…
AnalizadaMedia (5.4)0.31%—Palletsprojects Jinja23/12/202417/6/2026
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of if Jinja's sandbox is used. To exploit the vulnerability, an attacker needs to…
AplazadaCrítica (9.4)0.51%—Palletsprojects JinjaAI1/8/202417/6/2026
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever…
AplazadaAlta (7.5)1.2%—Deepset HaystackAIPocoo Jinja2AI31/7/202417/6/2026
Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone…
AplazadaCrítica (9.6)26%—Llama-cpp-pythonAIPocoo Jinja2AI14/5/202417/6/2026
llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA,…
ModificadaMedia (5.4)0.98%—Palletsprojects JinjaFedoraproject Fedora6/5/202417/6/2026
Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to…
AplazadaCrítica (10)84%—Changedetection.ioAIPocoo Jinja2AI26/4/202417/6/2026
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use…
ModificadaMedia (6.1)0.89%—Palletsprojects Jinja11/1/202417/6/2026
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary…
ModificadaMedia (6.5)1.8%—Hubspot Jinjava19/2/202117/6/2026
Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure.
ModificadaMedia (5.3)3.5%—Palletsprojects JinjaFedoraproject Fedora1/2/202117/6/2026
This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user…
ModificadaAlta (8.6)3.5%—Palletsprojects Jinja8/4/201917/6/2026
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
ModificadaAlta (8.6)3.6%—Palletsprojects JinjaFedoraproject FedoraCanonical Ubuntu LinuxRedhat Software Collections+17/4/201917/6/2026
In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
ModificadaCrítica (9.8)45%—Pocoo Jinja2Opensuse Leap15/2/201917/6/2026
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third…
ModificadaMedia (5.3)1.8%—Hubspot Jinjava3/1/201917/6/2026
Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
ModificadaMedia (4.4)0.38%—Pocoo Jinja219/5/201417/6/2026
The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp.