PT-2025-4850 · Docker · Docker Compose

M10X

·

Published

2025-01-28

·

Updated

2026-04-21

·

CVE-2025-23211

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Tandoor Recipes versions prior to 1.5.24
Description: The issue is related to a Jinja2 SSTI vulnerability that allows any user to execute commands on the server, potentially with root privileges in the case of the provided Docker Compose file. This vulnerability has been fixed in version 1.5.24.
Recommendations: Tandoor Recipes versions prior to 1.5.24: Update to version 1.5.24 to fix the Jinja2 SSTI vulnerability.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-23211
GHSA-R6RJ-H75W-VJ8V

Affected Products

Docker Compose