Jinja2 Server-Side Template Injection in Tandoor Recipes Application
CVE-2025-23211

9.9CRITICAL

Key Information:

Status
Vendor
CVE Published:
28 January 2025

What is CVE-2025-23211?

The Tandoor Recipes application, designed for managing recipes and meal planning, is affected by a Jinja2 Server-Side Template Injection vulnerability. This flaw allows unauthorized users to execute commands on the server, potentially compromising system security. The issue has been addressed in version 1.5.24, urging users to upgrade promptly to safeguard against possible exploit attempts.

Affected Version(s)

recipes < 1.5.24

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.