Template URI Handling Vulnerability in Mako Python Library
CVE-2026-102991
What is CVE-2026-102991?
The Mako template library, used extensively in Python applications, has a vulnerability in versions prior to 1.4.2 that allows attackers to manipulate template URIs. Specifically, the TemplateLookup.get_template() function resolves template URIs using posixpath, whereas Template.init() employs os.path for validation which defaults to ntpath on Windows systems. This discrepancy allows a URI starting with a drive designator to bypass security checks, enabling attackers to access and potentially execute unauthorized files within the application environment. This can result in sensitive data exposure or the execution of malicious templates if user-controlled input is not properly sanitized. The vulnerability has been addressed in release 1.4.2.
Affected Version(s)
mako < 1.4.2
