Vulnerability PYSEC-2026-88

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 23, 2026 at 07:17 PM UTC
No summary available
0.1.0 - 1.3.10
0.1.0 - 1.3.10

Details

Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.

Impacted packages

Timeline

Published
5 months ago
April 23, 2026 at 07:17 PM UTC
Fixed (1.3.11)
5 months ago
April 14, 2026 at 08:19 PM UTC
Last Modified
4 months ago
May 20, 2026 at 09:19 AM UTC