Executive brief
web.py is a Python web framework used as a library in downstream applications to build web services. The framework's Jinja2 template adapter fails to enable automatic HTML escaping by default, allowing attackers to inject malicious scripts into web pages when user-supplied data is rendered as template variables. An attacker can execute JavaScript in a victim's browser to steal session data, modify page content, or perform unauthorized actions.
Technical details
The Jinja2 adapter in web.py does not enable automatic escaping when creating the template environment, causing template variables to be written as raw strings into HTML output (CWE-79). Exploitation requires that a downstream application pass attacker-controllable data as template variables when rendering HTML templates through this adapter. The vulnerability affects the default configuration with no authentication, special setup, or user interaction beyond visiting a crafted page required; scripts execute in the victim's browser in the target site's origin, allowing session hijacking and same-site request forgery.
Affected products
- web.py web.py 0.76
Timeline
- 2026-09-22: disclosed
- 2026-08-03: other: Report date