Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pxrr-hq57-q35p | dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver |
Tue, 14 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:dynaconf:dynaconf:*:*:*:*:*:*:*:* |
Wed, 25 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-917 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dynaconf
Dynaconf dynaconf |
|
| Vendors & Products |
Dynaconf
Dynaconf dynaconf |
Fri, 20 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13. | |
| Title | dynaconf Affected by Remote Code Execution (RCE) via Insecure Template Evaluation in @jinja Resolver | |
| Weaknesses | CWE-1336 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-27T15:23:09.972Z
Reserved: 2026-03-17T21:17:08.886Z
Link: CVE-2026-33154
Updated: 2026-03-25T13:39:27.332Z
Status : Analyzed
Published: 2026-03-20T21:17:15.740
Modified: 2026-04-14T18:23:14.307
Link: CVE-2026-33154
OpenCVE Enrichment
Updated: 2026-04-15T16:45:09Z
Github GHSA