Junglewise Threat Intelligence

CVE-2026-33154: Dynaconf RCE via Insecure Template Evaluation in @jinja Resolver

CVE-2026-33154 · Severity: high · CVSS 7.5 · Published 2026-03-18

Vendors: PyPI.

Executive brief

Dynaconf, a configuration management library for Python, is vulnerable to a security flaw that allows attackers to execute malicious commands on a server. By manipulating configuration sources like environment variables or settings files, an attacker can gain full control over the application process or steal sensitive credentials like API keys and database passwords. This could lead to a total system compromise or significant data breaches.

Technical details

Dynaconf (<= 3.2.12) is vulnerable to Server-Side Template Injection (SSTI) in the @jinja resolver and object graph traversal in the @format resolver. The @jinja resolver evaluates template expressions without a sandbox, allowing attackers to access Python's internal attributes (e.g., via the 'cycler' object) to reach 'os.popen' and execute arbitrary OS commands. Simultaneously, the @format resolver allows traversal of the Python object graph to expose sensitive runtime objects and environment variables. Exploitation requires the attacker to influence configuration sources such as environment variables, .env files, or CI/CD secrets. The vulnerability is remediated in version 3.2.13 by implementing safer evaluation practices.

Affected products

  • dynaconf dynaconf <= 3.2.12

Timeline

  • 2026-03-18: disclosed
  • 2026-03-18: advisory: GitHub Advisory GHSA-pxrr-hq57-q35p published
  • 2026-03-18: patched: Version 3.2.13 released

References