Placeholder Injection Vulnerability in Pretix by Pretix GmbH
CVE-2026-2451
What is CVE-2026-2451?
Emails sent by the Pretix system utilize placeholders that can be substituted with customer data. However, a security issue exists where specially crafted placeholder names can be leveraged to exfiltrate sensitive information about the Pretix system. This vulnerability allows users with control over email templates to exploit the flaw, potentially revealing critical information such as database passwords or API keys from the system configuration. Although Pretix has attempted to implement safeguards against the use of malicious placeholders, a code oversight has rendered these protections ineffective. It is strongly advised to rotate all passwords and API keys stored in your configuration files as a precaution.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pretix-doistep 1.0.0 < 1.3.2
