VDB
Sign up
—

PYSEC-2026-1471

Jinja2 vulnerable to sandbox breakout through attr filter selecting format method

Quick fix

PYSEC-2026-1471 — jinja2: upgrade to the fixed version with the command below.

pip install --upgrade 'jinja2>=3.1.6'

Details

An oversight in how the Jinja sandboxed environment interacts with the `|attr` filter allows an attacker that controls the content of a template to execute arbitrary Python code.

To exploit the vulnerability, an attacker needs to control the content of a template. Whether that is the case depends on the type of application using Jinja. This vulnerability impacts users of applications which execute untrusted templates.

Jinja's sandbox does catch calls to `str.format` and ensures they don't escape the sandbox. However, it's possible to use the `|attr` filter to get a reference to a string's plain format method, bypassing the sandbox. After the fix, the `|attr` filter no longer bypasses the environment's attribute lookup.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/jinja2
Introduced in: 0Fixed in: 3.1.6
Fixpip install --upgrade 'jinja2>=3.1.6'

References