Executive brief
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Affected products
- PyPI jinja2
Junglewise Threat Intelligence
CVE-2025-27516 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: jinja2 (PyPI). Vendors: PyPI.
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method