Vulnerability PYSEC-2026-88
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 months ago
April 23, 2026 at 07:17 PM UTC
No summary available
0.1.0 - 1.3.10
0.1.0 - 1.3.10
Details
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can be returned as rendered template content when an application passes untrusted input directly to TemplateLookup.get_template(). This vulnerability is fixed in 1.3.11.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
8 hours ago
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
0.1.0 - 1.4.1 GHSA-5639-2j2p-m4mx
0.1.0 - 1.4.1 GHSA-5639-2j2p-m4mx
Unknown
2 months ago
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
0.1.0 - 1.3.11 PYSEC-2026-2617
0.1.0 - 1.3.11 PYSEC-2026-2617
High Risk
5 months ago
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
0.1.0 - 1.3.11 GHSA-2h4p-vjrc-8xpq
0.1.0 - 1.3.11 GHSA-2h4p-vjrc-8xpq
High Risk
5 months ago
Mako: Path traversal via double-slash URI prefix in TemplateLookup
0.1.0 - 1.3.10 GHSA-v92g-xgxw-vvmm
0.1.0 - 1.3.10 GHSA-v92g-xgxw-vvmm
High Risk
4 years ago
mako is vulnerable to Regular Expression Denial of Service
0.1.0 - 1.2.1 GHSA-v973-fxgf-6xhp
0.1.0 - 1.2.1 GHSA-v973-fxgf-6xhp
Impacted packages
Timeline
Published
5 months ago
April 23, 2026 at 07:17 PM UTC
Fixed (1.3.11)
5 months ago
April 14, 2026 at 08:19 PM UTC
Last Modified
4 months ago
May 20, 2026 at 09:19 AM UTC