| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
Jinja2 2.11.3 is affected by four CVEs: - CVE-2024-22195: XSS via xmlattr filter (fixed in 3.1.3) - CVE-2024-34064: XSS via xmlattr filter keys (fixed in 3.1.4) - CVE-2024-56326: Sandbox breakout via str.format (fixed in 3.1.5) - CVE-2025-27516: Sandbox breakout via attr filter (fixed in 3.1.6) MarkupSafe bumped from ==0.23 to >=2.1.0 as required by Jinja2 3.x. All tests pass (1609 pytest, 650 behave scenarios) on Python 3.12.
| Back | FazBrowse Home | New Git URL |
Jinja2 2.11.3 (currently pinned in [dependency-groups] dev) is affected by four CVEs:
Changes:
All tests pass on Python 3.12: 1609 pytest, 650 behave scenarios.
Supersedes #1322 which only bumps to 3.1.3 (missing two later CVEs).