Impact
The vulnerability is a directory traversal flaw that arises in the Mako template library when a Windows user supplies a URI that begins with a drive designator. In versions prior to 1.4.2, the lookup logic resolves the template path using posixpath, while the validation stage uses ntpath. This mismatch allows an attacker‑controlled template name or include path to escape the intended template directory, read files that are readable by the process, and, if the file contains Mako template syntax, have it parsed and executed as a template. The weakness is a CWE‑22 type input validation error.
Affected Systems
Mako, the Python templating library maintained by SQLAlchemy, is affected in all releases earlier than 1.4.2 when running on Windows. The flaw is specific to Windows file‑system handling and only impacts applications that invoke TemplateLookup.get_template() with untrusted or dynamic URI values.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the medium severity range. Exploit probability is not reported (EPSS not available) and the vulnerability is not listed in CISA’s KEV catalog, implying that it has not yet been widely exploited. However, the attack requires that an attacker can influence the template name or include path, which can occur in many web applications or services that accept user‑supplied template parameters. If exploit is possible, the attacker can read any process‑readable file on the same volume and potentially trigger template rendering of malicious content, leading to information disclosure and possibly code execution in the context of the running application.
OpenCVE Enrichment