Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v92g-xgxw-vvmm | Mako: Path traversal via double-slash URI prefix in TemplateLookup |
Ubuntu USN |
USN-8234-1 | Mako vulnerability |
Tue, 28 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sqlalchemy:mako:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 27 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sqlalchemy
Sqlalchemy mako |
|
| Vendors & Products |
Sqlalchemy
Sqlalchemy mako |
Sun, 26 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 23 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 23 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11. | |
| Title | Mako: Path traversal via double-slash URI prefix in TemplateLookup | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-23T20:20:59.107Z
Reserved: 2026-04-18T02:51:52.974Z
Link: CVE-2026-41205
Updated: 2026-04-23T20:20:55.667Z
Status : Analyzed
Published: 2026-04-23T19:17:29.270
Modified: 2026-04-28T19:14:56.553
Link: CVE-2026-41205
OpenCVE Enrichment
Updated: 2026-04-28T07:45:26Z
Github GHSA
Ubuntu USN