CVE-2026-5559
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the f
CVSS
6.3
Medio
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 5 abr 2026 · Última mod.: 24 jul 2026 · CWE-791 · CWE-1336
0.3%EPSS · 30 días0.3%
2026-08-142026-09-10
A vulnerability has been found in AntaresMugisho PyBlade 0.1.8-alpha/0.1.9-alpha. The affected element is the function _is_safe_ast of the file sandbox.py of the component AST Validation. Such manipulation leads to improper neutralization of special elements used in a template engine. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
- github.comhttps://github.com/AntaresMugisho/PyBlade/
- github.comhttps://github.com/AntaresMugisho/PyBlade/issues/1
- github.comhttps://github.com/AntaresMugisho/PyBlade/issues/1#issue-4086730906
- vuldb.comhttps://vuldb.com/submit/782904
- vuldb.comhttps://vuldb.com/vuln/355329
- vuldb.comhttps://vuldb.com/vuln/355329/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-81910——
———Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Template Injection (SSTI) in Theme Customizer via Unvalidated Style Values. Values submitted through the customizer (color channels and other style properties handled by ColorStyle and sibling Style classes such as FontFamilyStyle and ImageStyle) are interpolated into server-compiled LESS source without neutralization of LESS syntax, allowing a user with the Theme Customization permission to inject arbitrary LESS directives. By injecting the @import (inline) directive, an attacker can read arbitrary files on the server and reach internal network resources through PHP stream wrappers. The compiled output, including any disclosed file contents, is written to the site's publicly served CSS cache, exposing database credentials, private keys, and other application secrets, and enabling server-side request forgery. The Concrete CMS security team gave this vulnerability a CVSS v4.0 score of 5.9 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori from Tenzai for reporting.16hCVE-2026-91604.3 MED—
———Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection.
This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.16hCVE-2026-890949.9 CRÍ—
——0Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.2dCVE-2026-195847.7 ALT8.7%
——3Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored.1dCVE-2026-870217.2 ALT30.3%
——9Tanium addressed an unauthorized code execution vulnerability in Comply.3dCVE-2026-333874.6 MED7.4%
——2A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required privileges can define a dashboard containing a malicious payload, or a victim can be socially engineered into importing a malicious dashboard. When the victim views or imports the dashboard, the payload executes in their browser context, allowing the attacker to modify application data or disrupt application availability.4d