{"id":"GHSA-q2x7-8rv6-6q7h","summary":"Jinja has a sandbox breakout through indirect reference to format method","details":"An oversight in how the Jinja sandboxed environment detects calls to `str.format` allows an attacker that controls the content of a template to execute arbitrary Python code.\n\nTo exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates.\n\nJinja's sandbox does catch calls to `str.format` and ensures they don't escape the sandbox. However, it's possible to store a reference to a malicious string's `format` method, then pass that to a filter that calls it. No such filters are built-in to Jinja, but could be present through custom filters in an application. After the fix, such indirect calls are also handled by the sandbox.","aliases":["CVE-2024-56326","PYSEC-2026-1475"],"modified":"2026-07-07T17:56:44.376174317Z","published":"2024-12-23T17:56:08Z","related":["CGA-vf88-6cvh-mxch"],"database_specific":{"cwe_ids":["CWE-693"],"github_reviewed_at":"2024-12-23T17:56:08Z","github_reviewed":true,"nvd_published_at":"2024-12-23T16:15:07Z","severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/pallets/jinja/security/advisories/GHSA-q2x7-8rv6-6q7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-56326"},{"type":"WEB","url":"https://github.com/pallets/jinja/commit/48b0687e05a5466a91cd5812d604fa37ad0943b4"},{"type":"PACKAGE","url":"https://github.com/pallets/jinja"},{"type":"WEB","url":"https://github.com/pallets/jinja/releases/tag/3.1.5"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00022.html"}],"affected":[{"package":{"name":"jinja2","ecosystem":"PyPI","purl":"pkg:pypi/jinja2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.5"}]}],"versions":["2.0","2.0rc1","2.1","2.1.1","2.10","2.10.1","2.10.2","2.10.3","2.11.0","2.11.1","2.11.2","2.11.3","2.2","2.2.1","2.3","2.3.1","2.4","2.4.1","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6","2.7","2.7.1","2.7.2","2.7.3","2.8","2.8.1","2.9","2.9.1","2.9.2","2.9.3","2.9.4","2.9.5","2.9.6","3.0.0","3.0.0a1","3.0.0rc1","3.0.0rc2","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4"],"database_specific":{"last_known_affected_version_range":"\u003c= 3.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-q2x7-8rv6-6q7h/GHSA-q2x7-8rv6-6q7h.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}