jinja2 vulnerabilities
CVEs whose affected-version data names the jinja2 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2025-27516Medium· 7.3Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
▾ Sunlitjinja2 · jinja2EPSS 0.50%via OSV
CVE-2024-56326High· 7.8Jinja has a sandbox breakout through indirect reference to format method
Jinja has a sandbox breakout through indirect reference to format method
▾ Twilightjinja2 · jinja2EPSS 0.52%via OSV
CVE-2024-56201High· 8.8Jinja has a sandbox breakout through malicious filenames
Jinja has a sandbox breakout through malicious filenames
▾ Twilightjinja2 · jinja2EPSS 0.31%via OSV
CVE-2024-34064Medium· 5.4PoCJinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
▾ Twilightjinja2 · jinja2EPSS 0.98%via OSV
CVE-2024-22195Medium· 5.4Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
▾ Sunlitjinja2 · jinja2EPSS 0.89%via OSV