python-jinja2: command injection in function from_string
Published Feb 15, 2019
9.8
CRITICALCVSS 3.1
EPSS 44.78%
Description
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing
Affected products
No data.
No data.
Red Hat Ceph Storage 2
python-jinja2
Not affected
Red Hat Ceph Storage 3
python-jinja2
Not affected
Red Hat Enterprise Linux 6
python-jinja2
Not affected
Red Hat Enterprise Linux 7
python-jinja2
Not affected
Red Hat Enterprise Linux 8
python-jinja2
Not affected
Red Hat OpenStack Platform 13 (Queens)
python-jinja2
Not affected
Red Hat OpenStack Platform 14 (Rocky)
python-jinja2
Not affected
Red Hat Satellite 6
python-jinja2
Not affected
Red Hat Storage 3
python-jinja2
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | python-jinja2 | Not affected | n/a |
| Red Hat Ceph Storage 3 | python-jinja2 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | python-jinja2 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python-jinja2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python-jinja2 | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-jinja2 | Not affected | n/a |
| Red Hat OpenStack Platform 14 (Rocky) | python-jinja2 | Not affected | n/a |
| Red Hat Satellite 6 | python-jinja2 | Not affected | n/a |
| Red Hat Storage 3 | python-jinja2 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security does not believe this CVE assignment is valid. To the best of our knowledge, Jinja2 does not make any guarantees about being able to safely handle untrusted data by default without sandboxing modes enabled.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 44.78% (0.44780) | 98.74th | v5 (v2026.06.15) |
| Jun 15, 2026 | 44.78% (0.44780) | 98.61th | v5 (v2026.06.15) |
| Apr 23, 2026 | 25.41% (0.25411) | 96.23th | v4 (v2025.03.14) |
| Jan 16, 2026 | 36.59% (0.36588) | 97.00th | v4 (v2025.03.14) |
| Nov 23, 2025 | 37.80% (0.37804) | 97.02th | v4 (v2025.03.14) |
| Nov 21, 2025 | 36.36% (0.36360) | 96.93th | v4 (v2025.03.14) |
| Nov 18, 2025 | 69.39% (0.69391) | 98.68th | v4 (v2025.03.14) |
| Nov 14, 2025 | 36.36% (0.36360) | 96.93th | v4 (v2025.03.14) |
| Nov 13, 2025 | 27.84% (0.27837) | 96.24th | v4 (v2025.03.14) |
| Jul 24, 2025 | 22.01% (0.22008) | 95.51th | v4 (v2025.03.14) |
| Apr 30, 2025 | 20.71% (0.20708) | 95.21th | v4 (v2025.03.14) |
| Apr 6, 2025 | 23.35% (0.23348) | 95.50th | v4 (v2025.03.14) |
| Mar 30, 2025 | 29.37% (0.29371) | 96.20th | v4 (v2025.03.14) |
| Mar 29, 2025 | 36.65% (0.36654) | 95.60th | v4 (v2025.03.14) |
| Mar 28, 2025 | 29.37% (0.29371) | 96.20th | v4 (v2025.03.14) |
| Mar 27, 2025 | 36.65% (0.36654) | 96.60th | v4 (v2025.03.14) |
| Mar 20, 2025 | 29.37% (0.29371) | 96.22th | v4 (v2025.03.14) |
| Mar 19, 2025 | 36.65% (0.36654) | 96.66th | v4 (v2025.03.14) |
| Mar 17, 2025 | 29.37% (0.29371) | 96.19th | v4 (v2025.03.14) |
| Dec 17, 2024 | 2.25% (0.02251) | 89.22th | v3 (v2023.03.01) |
| Jul 8, 2024 | 3.49% (0.03491) | 91.60th | v3 (v2023.03.01) |
| Apr 3, 2024 | 4.25% (0.04245) | 92.09th | v3 (v2023.03.01) |
| Mar 15, 2024 | 6.01% (0.06009) | 93.30th | v3 (v2023.03.01) |
| Feb 27, 2024 | 5.58% (0.05576) | 93.03th | v3 (v2023.03.01) |
| Feb 9, 2024 | 5.67% (0.05668) | 93.02th | v3 (v2023.03.01) |
| Jan 25, 2024 | 5.65% (0.05648) | 92.58th | v3 (v2023.03.01) |
| Jan 7, 2024 | 6.37% (0.06365) | 92.93th | v3 (v2023.03.01) |
| Jun 11, 2023 | 4.69% (0.04686) | 91.42th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.85% (0.04849) | 91.47th | v3 (v2023.03.01) |
| Mar 6, 2023 | 10.21% (0.10212) | 94.60th | v2 (v2022.01.01) |
| Apr 1, 2022 | 10.21% (0.10212) | 94.14th | v2 (v2022.01.01) |
| Feb 4, 2022 | 30.49% (0.30487) | 96.34th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Jan 6, 2022 | 6.21% (0.06208) | 81.75th | v1 |
| Sep 1, 2021 | 6.21% (0.06208) | 89.66th | v1 |
| Apr 14, 2021 | 6.21% (0.06208) | 0.00th | v1 |
References (9)
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-8341 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1677653 x_refsource_MISCIssue TrackingThird Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1125815 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/JameelNabbo/Jinja2-Code-execution x_refsource_MISCBroken Link
- https://nvd.nist.gov/vuln/detail/CVE-2019-8341
- https://www.cve.org/CVERecord?id=CVE-2019-8341
- https://www.exploit-db.com/exploits/46386/ exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00030.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00064.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-8341 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1677653 | x_refsource_MISCIssue TrackingThird Party Advisory | |
| https://bugzilla.suse.com/show_bug.cgi?id=1125815 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/JameelNabbo/Jinja2-Code-execution | x_refsource_MISCBroken Link | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-8341 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-8341 | ||
| https://www.exploit-db.com/exploits/46386/ | exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.