CVE-2026-2415: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-2415 is a template injection vulnerability in the pretix event ticketing platform affecting its email placeholder mechanism. Attackers with backend access can craft malicious placeholder expressions (e.g., {{event.__init__.__code__.co_filename}}) to exfiltrate sensitive system configuration data, including database passwords and API keys. A secondary bug causes double evaluation of placeholders in email subjects and plain text bodies, potentially allowing ticket buyers to trigger the same information disclosure via buyer-controlled fields such as {invoice_company}. Affected versions span pretix 4.16.0 through 2026.1.0 (inclusive); version 2026.1.1 resolves the issue. The CVSS v3.1 base score is 5.9 (Medium), while the CVSS v4.0 base score is 7.5 (High) (Feedly, pretix Blog).

Technical details

The root cause is classified as CWE-627 (Dynamic Variable Evaluation). Pretix's email templating engine resolves placeholder expressions against Python object attributes without fully sanitizing the namespace, allowing traversal of internal Python objects via attribute chains (e.g., __init__.__code__.co_filename). A separate logic flaw causes placeholders in email subjects and plain text bodies to be evaluated twice: if the first evaluation produces a string containing another placeholder, that second placeholder is also rendered. This double-evaluation means buyer-controlled data fields (like {invoice_company}) can be weaponized to inject and trigger malicious placeholder expressions, even without backend access. The protection mechanisms intended to block such traversal were present but not fully applied to the email subject field (Feedly, pretix Blog).

Impact

Successful exploitation can expose highly sensitive configuration data from the pretix server, including database credentials and API keys stored in pretix.cfg. Backend users (typically any pretix staff account) can directly exfiltrate this data via crafted email templates, while the double-evaluation bug extends partial exposure risk to unauthenticated ticket buyers under specific configurations. Confidentiality impact is high; integrity and availability are not directly affected by this vulnerability, though compromised credentials could enable further attacks such as database access or API abuse (Feedly).

Exploitability

No public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation as of the time of reporting. The CVSS v4.0 exploit maturity is rated "Proof of Concept," suggesting the technique is theoretically demonstrable but not yet weaponized. The EPSS score is approximately 0.047%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Attack complexity is rated High, as exploitation requires either backend access or a specific buyer-controlled field configuration (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a pretix instance running versions 4.16.0 through 2026.1.0. Determine whether you have backend (staff) access or, alternatively, whether the target uses {invoice_company} in email subject templates.
  2. Backend path — craft malicious template: Log in to the pretix backend with any staff account. Navigate to email template configuration and insert a specially crafted placeholder such as {{event.__init__.__code__.co_filename}} or {{event.__init__.__globals__}} into an email template subject or body.
  3. Trigger email send: Trigger an action that causes pretix to send an email using the modified template (e.g., completing a test order or sending a manual notification).
  4. Collect exfiltrated data: The rendered email will contain the resolved value of the Python object attribute — potentially revealing file paths, configuration values, database passwords, or API keys.
  5. Buyer path (double-evaluation): As a ticket buyer, set the invoice_company field to a malicious placeholder string (e.g., {{event.__init__.__code__.co_filename}}). If the target's email subject template includes {invoice_company} and double-evaluation is present, the injected placeholder will be rendered in the outgoing email, disclosing sensitive data (Feedly, pretix Blog).

Indicators of compromise

  • Logs: Pretix application logs showing email template renders containing Python dunder attribute chains (e.g., __init__, __code__, __globals__, co_filename) in subject or body fields.
  • Email Content: Outbound emails containing file system paths, configuration file contents, or raw Python object representations in the subject or body.
  • Database/Config Audit: Unexpected access to pretix.cfg values or API keys appearing in email logs or sent message archives.
  • User Activity: Backend audit logs showing email template modifications by non-administrative staff accounts, particularly changes introducing {{...}} double-brace expressions.
  • Order Data: Ticket orders where the invoice_company field contains placeholder syntax (e.g., {{event.*}}) rather than a legitimate company name.

Mitigation and workarounds

Upgrade pretix to version 2026.1.1 or later, which contains fixes for both the incomplete placeholder sanitization in email subjects and the double-evaluation logic flaw (pretix Blog). As an immediate precaution, rotate all passwords and API keys stored in pretix.cfg, as these may have been exposed if the system ran a vulnerable version. Restrict email template editing permissions to trusted administrators only, and audit existing email templates for any suspicious placeholder expressions containing Python attribute traversal syntax. No configuration-only workaround fully mitigates the vulnerability without upgrading.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management