PT-2024-9991 · Jinja+11 · Jinja+11

Lydxn

·

Published

2024-12-20

·

Updated

2026-06-03

·

CVE-2024-56326

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jinja versions prior to 3.1.5
Description Jinja is an extensible templating engine. An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that controls the content of a template to execute arbitrary Python code. To exploit the issue, an attacker needs to control the content of a template, which depends on the type of application using Jinja. This affects users of applications that execute untrusted templates. Jinja's sandbox catches calls to str.format but does not prevent storing a reference to a malicious string's format method and passing it to a filter that calls it. Custom filters in an application could be used to exploit this.
Recommendations For versions prior to 3.1.5, update to version 3.1.5 or later to fix the vulnerability. As a temporary workaround, consider restricting the use of custom filters in applications that execute untrusted templates.

Exploit

Fix

DoS

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALSA-2025:0308
ALSA-2025:0667
ALSA-2025:0711
ALSA-2025_0667
ALSA-2025_0711
ALT-PU-2025-11958
ALT-PU-2025-12986
AZL-54647
AZL-54654
BDU:2025-00113
CESA-2025_0711
CVE-2024-56326
DLA-4126-1
ECHO-1D31-DACB-27DA
GHSA-Q2X7-8RV6-6Q7H
INFSA-2025_0308
INFSA-2025_0667
INFSA-2025_0711
MGASA-2025-0050
OESA-2024-2597
OESA-2024-2598
OESA-2025-1004
OESA-2025-1005
OESA-2025-1006
OESA-2025-1030
OPENSUSE-SU-2025:14997-1
OPENSUSE-SU-2025_0006-1
OPENSUSE-SU-2025_0029-1
RHSA-2025:0308
RHSA-2025:0335
RHSA-2025:0338
RHSA-2025:0345
RHSA-2025:0656
RHSA-2025:0667
RHSA-2025:0711
RHSA-2025:0721
RHSA-2025:0777
RHSA-2025:0830
RHSA-2025:0834
RHSA-2025:0842
RHSA-2025:0850
RHSA-2025:0883
RHSA-2025:0950
RHSA-2025:0951
RHSA-2025:0978
RHSA-2025:1109
RHSA-2025:1118
RHSA-2025:1130
RHSA-2025:1250
RHSA-2025:1861
RHSA-2025:2399
RHSA-2025:2612
RHSA-2025:4576
RHSA-2025_0308
RHSA-2025_0667
RHSA-2025_0711
RLSA-2025:0308
RLSA-2025:0667
RLSA-2025:0711
ROSA-SA-2025-2762
SUSE-SU-2025:0006-1
SUSE-SU-2025:0016-1
SUSE-SU-2025:0029-1
SUSE-SU-2025:20117-1
SUSE-SU-2025:20254-1
SUSE-SU-2025_0016-1
SUSE-SU-2025_0029-1
USN-7244-1
USN-7343-1
USN-7343-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Jinja
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu