Количество 7
Количество 7
CVE-2026-44307
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.
CVE-2026-44307
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.
CVE-2026-44307
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.
CVE-2026-44307
Mako: Path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-44307
Mako is a template library written in Python. Prior to 1.3.12, on Wind ...
ROS-20260713-73-0041
Уязвимость python-mako
GHSA-2h4p-vjrc-8xpq
Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-44307 Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12. | 1% Низкий | 3 месяца назад | ||
CVE-2026-44307 Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12. | CVSS3: 5.9 | 1% Низкий | 3 месяца назад | |
CVE-2026-44307 Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12. | 1% Низкий | 3 месяца назад | ||
CVE-2026-44307 Mako: Path traversal via backslash URI on Windows in TemplateLookup | 1% Низкий | 3 месяца назад | ||
CVE-2026-44307 Mako is a template library written in Python. Prior to 1.3.12, on Wind ... | 1% Низкий | 3 месяца назад | ||
ROS-20260713-73-0041 Уязвимость python-mako | CVSS3: 7.5 | 1% Низкий | 20 дней назад | |
GHSA-2h4p-vjrc-8xpq Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup | 1% Низкий | 3 месяца назад |
Уязвимостей на страницу