Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2617▼ 302 respecto a la semana anterior
Críticas / altas1346▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.7) | 0.27% | — | Palletsprojects JinjaAI | 23/9/2026 | 25/9/2026 | — | |
| Aplazada | Baja (2.1) | 0.39% | — | Langgenius DifyAIPocoo Jinja2AI | 3/8/2026 | 12/8/2026 | A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of special elements used in a template engine.… | |
| Aplazada | Baja (2.1) | 0.47% | — | Jcharis Machine-learning-web-appsAIPocoo Jinja2AI | 11/3/2026 | 17/6/2026 | A vulnerability was identified in Jcharis Machine-Learning-Web-Apps up to a6996b634d98ccec4701ac8934016e8175b60eb5. The impacted element is the function render_template of the file Machine-Learning-Web-Apps-master/Build-n-Deploy-Flask-App-with-Waypoint/app/app.py of the component Jinja2 Template Handler. Such… | |
| Analizada | Crítica (9.8) | 1.0% | — | Hubspot Jinjava | 4/2/2026 | 17/6/2026 | JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file access bypassing built-in sandbox… | |
| Analizada | Crítica (10) | 2.1% | — | Hubspot Jinjava | 17/9/2025 | 17/6/2026 | jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2.8.1, by using mapper.getTypeFactory().constructFromCanonical(), it is possible to instruct the underlying ObjectMapper to deserialize attacker-controlled input into arbitrary classes. This enables… | |
| Aplazada | Alta (8.5) | 20% | — | SkyvernAIPalletsprojects JinjaAI | 7/6/2025 | 17/6/2026 | Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code… | |
| Aplazada | Media (4.8) | 0.23% | — | Sarrionandia TournatrackAIPalletsprojects JinjaAI | 19/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in sarrionandia tournatrack up to 4c13a23f43da5317eea4614870a7a8510fc540ec. Affected by this vulnerability is an unknown functionality of the file check_id.py of the component Jinja2 Template Handler. The manipulation of the argument ID leads to injection. It is… | |
| Aplazada | Media (4.8) | 0.23% | — | Thautwarm Vscode-dianaAIPalletsprojects JinjaAI | 19/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | |
| Modificada | Media (5.4) | 0.51% | — | Palletsprojects JinjaDebian Linux | 5/3/2025 | 17/6/2026 | Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a… | |
| Aplazada | Alta (7.8) | 0.34% | — | AptrsAIDjangoAIPalletsprojects JinjaAI | 23/12/2024 | 17/6/2026 | APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is a vulnerability in the web application's handling of user-supplied input that is incorporated into a Jinja2 template. Specifically,… | |
| Modificada | Media (5.4) | 0.52% | — | Palletsprojects Jinja | 23/12/2024 | 17/6/2026 | Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the vulnerability, an attacker needs to control the content of a template.… | |
| Analizada | Media (5.4) | 0.31% | — | Palletsprojects Jinja | 23/12/2024 | 17/6/2026 | Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls both the content and filename of a template to execute arbitrary Python code, regardless of if Jinja's sandbox is used. To exploit the vulnerability, an attacker needs to… | |
| Aplazada | Crítica (9.4) | 0.51% | — | Palletsprojects JinjaAI | 1/8/2024 | 17/6/2026 | Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever… | |
| Aplazada | Alta (7.5) | 1.2% | — | Deepset HaystackAIPocoo Jinja2AI | 31/7/2024 | 17/6/2026 | Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone… | |
| Aplazada | Crítica (9.6) | 26% | — | Llama-cpp-pythonAIPocoo Jinja2AI | 14/5/2024 | 17/6/2026 | llama-cpp-python is the Python bindings for llama.cpp. `llama-cpp-python` depends on class `Llama` in `llama.py` to load `.gguf` llama.cpp or Latency Machine Learning Models. The `__init__` constructor built in the `Llama` takes several parameters to configure the loading and running of the model. Other than `NUMA,… | |
| Modificada | Media (5.4) | 0.98% | — | Palletsprojects JinjaFedoraproject Fedora | 6/5/2024 | 17/6/2026 | Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to… | |
| Aplazada | Crítica (10) | 84% | — | Changedetection.ioAIPocoo Jinja2AI | 26/4/2024 | 17/6/2026 | changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use… | |
| Modificada | Media (6.1) | 0.89% | — | Palletsprojects Jinja | 11/1/2024 | 17/6/2026 | Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject arbitrary HTML attributes into the rendered HTML template, potentially leading to Cross-Site Scripting (XSS). The Jinja `xmlattr` filter can be abused to inject arbitrary… | |
| Modificada | Media (6.5) | 1.8% | — | Hubspot Jinjava | 19/2/2021 | 17/6/2026 | Jinjava before 2.5.4 allow access to arbitrary classes by calling Java methods on objects passed into a Jinjava context. This could allow for abuse of the application class loader, including Arbitrary File Disclosure. | |
| Modificada | Media (5.3) | 3.5% | — | Palletsprojects JinjaFedoraproject Fedora | 1/2/2021 | 17/6/2026 | This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the most exploitable as it searches for trailing punctuation. This issue can be mitigated by Markdown to format user… | |
| Modificada | Alta (8.6) | 3.5% | — | Palletsprojects Jinja | 8/4/2019 | 17/6/2026 | In Pallets Jinja before 2.8.1, str.format allows a sandbox escape. | |
| Modificada | Alta (8.6) | 3.6% | — | Palletsprojects JinjaFedoraproject FedoraCanonical Ubuntu LinuxRedhat Software Collections+1 | 7/4/2019 | 17/6/2026 | In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape. | |
| Modificada | Crítica (9.8) | 45% | — | Pocoo Jinja2Opensuse Leap | 15/2/2019 | 17/6/2026 | An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third… | |
| Modificada | Media (5.3) | 1.8% | — | Hubspot Jinjava | 3/1/2019 | 17/6/2026 | Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java. | |
| Modificada | Media (4.4) | 0.38% | — | Pocoo Jinja2 | 19/5/2014 | 17/6/2026 | The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file with a name starting with __jinja2_ in /tmp. |