<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:11:50 +0000</lastBuildDate>
    <item>
      <title>BREW-ansible-cmdb-CVE-2026-44307 — Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2026-44307</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: ansible-cmdb&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-ansible-cmdb-cve-2026-44307</guid>
    </item>
    <item>
      <title>CVE-2026-44307 — Mako: Path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-44307</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sqlalchemy mako&lt;/p&gt;
&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; sqlalchemy mako&lt;/p&gt;
&lt;p&gt;Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in TemplateLookup.get_template(), allowing reads of files outside the configured template directory. This vulnerability is fixed in 1.3.12.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-44307</guid>
    </item>
    <item>
      <title>GHSA-2h4p-vjrc-8xpq — Mako vulnerable to path traversal via backslash URI on Windows in TemplateLookup</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2h4p-vjrc-8xpq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Mako&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;On Windows, a URI using backslash traversal (e.g. `\..\..\ secret.txt`) bypasses the directory traversal check in `Template.__init__` and the `posixpath`-based normalization in `TemplateLookup.get_template()`, allowing reads of files outside the configured template directory.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The root cause is a mismatch between `posixpath` (used for URI normalization in `get_template()`) and `os.path` (used for file access via `os.path.isfile()` and validation via `os.path.normpath()` in `Template.__init__`). On Windows, `os.path` is `ntpath`, which treats `\` as a path separator, while `posixpath` treats it as a literal character.&lt;/p&gt;
&lt;p&gt;The vulnerability chain:&lt;/p&gt;
&lt;p&gt;1. `get_template()` strips only leading `/` via `re.sub(r&amp;#34;^\/+&amp;#34;, &amp;#34;&amp;#34;, uri)` and normalizes with `posixpath` — backslash `\` is treated as a literal character, so `\..\ secret.txt` passes through with `..` undetected.
2. `Template.__init__()` validation uses `os.path.normpath()` — on Windows this resolves `\..\ secret.txt` to `\secret.txt`, which does not start with `..`, so the `startswith(&amp;#34;..&amp;#34;)` check passes.
3. `os.path.isfile()` on Windows interprets `\` as a path separator, resolving the `..` traversal and finding files outside the template directory.&lt;/p&gt;
&lt;p&gt;### Affected code&lt;/p&gt;
&lt;p&gt;- `mako/lookup.py`: `TemplateLookup.get_template()` uses `posixpath.normpath`/`posixpath.join` for path construction but `os.path.isfile()` for existence check
- `mako/template.py`: `Template.__init__()` URI validation uses `os.path.normpath…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2h4p-vjrc-8xpq</guid>
    </item>
  </channel>
</rss>
