{"id":"CVE-2020-28468","details":"This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code execution.","aliases":["GHSA-7xc5-ggpp-g249","PYSEC-2021-72","SNYK-PYTHON-PWNTOOLS-1047345"],"modified":"2026-07-09T00:22:14.088826Z","published":"2021-01-08T12:15:12.687Z","references":[{"type":"REPORT","url":"https://github.com/Gallopsled/pwntools/issues/1427"},{"type":"FIX","url":"https://github.com/Gallopsled/pwntools/pull/1732"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-PYTHON-PWNTOOLS-1047345"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gallopsled/pwntools","events":[{"introduced":"0"},{"fixed":"957a5a58356d25f2d5b99da27cb2a57b8665d2ca"}],"database_specific":{"cpe":"cpe:2.3:a:pwntools_project:pwntools:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.3.1"}],"source":"CPE_RANGE"}}],"versions":["4.3.0","4.3.0beta0","4.2.0beta0","4.1.0beta0","4.0.0beta0","3.13.0beta0","3.12.0","3.11.0","3.11.0beta0","3.10.0beta0","3.9.0beta0","3.8.0beta0","3.7.0beta0","3.6.0beta0","3.5.0beta0","3.4.0beta0","3.3.0","3.2.0","3.3.0beta0","3.2.0beta5","3.2.0beta4","3.2.0beta3","3.2.0beta2","3.2.0beta1","3.2.0beta0","3.0.0","2.3.0","2.2.0","2.2","2.1.3","2.1.2","2.1.1","2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28468.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}