Template URI Handling Vulnerability in Mako Python Library
CVE-2026-102991

6.5MEDIUM

Key Information:

Vendor

Sqlalchemy

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102991?

The Mako template library, used extensively in Python applications, has a vulnerability in versions prior to 1.4.2 that allows attackers to manipulate template URIs. Specifically, the TemplateLookup.get_template() function resolves template URIs using posixpath, whereas Template.init() employs os.path for validation which defaults to ntpath on Windows systems. This discrepancy allows a URI starting with a drive designator to bypass security checks, enabling attackers to access and potentially execute unauthorized files within the application environment. This can result in sensitive data exposure or the execution of malicious templates if user-controlled input is not properly sanitized. The vulnerability has been addressed in release 1.4.2.

Affected Version(s)

mako < 1.4.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.