Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102991— Mako: Path traversal via drive-letter URI on Windows in TemplateLookup

Quick assessment

Affected
sqlalchemy mako
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mako 是一个用 Python 编写的模板库。在 1.4.2 版本之前,在 Windows 系统上, 中的 方法使用 来解析模板 URI,而 中的 方法则使用 (在 Windows 上底层为 )对其进行验证。当 URI 以驱动器盘符(如 )开头时, 会在执行前导的“..”(双点)检查之前吸收路径中的遍历段,而 的解析逻辑却可能允许路径逃逸出配置的模板目录。因此,如果应用程序将攻击者可控的模板名称或包含(include)路径传入该函数,就可能泄露同一磁盘卷上进程可读的文件;此外,若目标文件包含 Mako 模板语法,

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1059.006 · Python
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102991

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
Source: CVE Program / CVE List V5
Vulnerability Description
Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sqlalchemy mako < 1.4.2 -

II. Public POCs for CVE-2026-102991

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102991

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-102991 (1)

Vendor Advisories for CVE-2026-102991 (1)

Vendor Pages for CVE-2026-102991 (1)

Other References for CVE-2026-102991 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102991

No comments yet


Leave a comment