{"id":"CVE-2026-35477","title":"InvenTree is an Open Source Inventory Management System","summary":"InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py …","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-1336"],"vendor":"inventree_project","product":"inventree","affected":["inventree >= 1.2.3, <= 1.2.6"],"published":"2026-04-08","updated":"2026-10-06","sourceUpdated":"2026-10-06T22:10:00.247","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-35477","references":[{"url":"https://github.com/inventree/InvenTree/security/advisories/GHSA-84jh-x777-8pqq","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00363,"epssPercentile":0.27978,"ingestedAt":"2026-10-06T22:23:15.919Z","slug":"CVE-2026-35477","body":"## Overview\n\nInvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PART_NAME_FORMAT validator to use jinja2.sandbox.SandboxedEnvironment. However, the actual renderer in part/helpers.py was not updated and still uses the non-sandboxed jinja2.Environment. Additionally, the validator uses a dummy Part instance with pk=None, which allows conditional template expressions to behave differently during validation versus production rendering. A staff user with settings access can craft a template that passes validation but executes arbitrary code during rendering. This issue requires access by a user with granted staff permissions. This vulnerability is fixed in 1.2.7 and 1.3.0.\n\n## Affected\n\n- `inventree >= 1.2.3, <= 1.2.6`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}