In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
Published: 2019-04-07
CVSS: 8.6
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Download Exploit for CVE-2019-10906 here:
Tip: Download official Tor Browser at https://www.torproject.org/download/ to access .onion links.
https://augustaverburg.nl/exploit-335-cve-2024-0769/
https://augustaverburg.nl/exploit-683-cve-2023-39017/
https://augustaverburg.nl/exploit-401-cve-2024-3596/
https://augustaverburg.nl/exploit-546-cve-2023-34058/
https://augustaverburg.nl/exploit-226-cve-2025-33070/
