
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2415 is a template injection vulnerability in the pretix event ticketing platform affecting its email placeholder mechanism. Attackers with backend access can craft malicious placeholder expressions (e.g., {{event.__init__.__code__.co_filename}}) to exfiltrate sensitive system configuration data, including database passwords and API keys. A secondary bug causes double evaluation of placeholders in email subjects and plain text bodies, potentially allowing ticket buyers to trigger the same information disclosure via buyer-controlled fields such as {invoice_company}. Affected versions span pretix 4.16.0 through 2026.1.0 (inclusive); version 2026.1.1 resolves the issue. The CVSS v3.1 base score is 5.9 (Medium), while the CVSS v4.0 base score is 7.5 (High) (Feedly, pretix Blog).
The root cause is classified as CWE-627 (Dynamic Variable Evaluation). Pretix's email templating engine resolves placeholder expressions against Python object attributes without fully sanitizing the namespace, allowing traversal of internal Python objects via attribute chains (e.g., __init__.__code__.co_filename). A separate logic flaw causes placeholders in email subjects and plain text bodies to be evaluated twice: if the first evaluation produces a string containing another placeholder, that second placeholder is also rendered. This double-evaluation means buyer-controlled data fields (like {invoice_company}) can be weaponized to inject and trigger malicious placeholder expressions, even without backend access. The protection mechanisms intended to block such traversal were present but not fully applied to the email subject field (Feedly, pretix Blog).
Successful exploitation can expose highly sensitive configuration data from the pretix server, including database credentials and API keys stored in pretix.cfg. Backend users (typically any pretix staff account) can directly exfiltrate this data via crafted email templates, while the double-evaluation bug extends partial exposure risk to unauthenticated ticket buyers under specific configurations. Confidentiality impact is high; integrity and availability are not directly affected by this vulnerability, though compromised credentials could enable further attacks such as database access or API abuse (Feedly).
No public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation as of the time of reporting. The CVSS v4.0 exploit maturity is rated "Proof of Concept," suggesting the technique is theoretically demonstrable but not yet weaponized. The EPSS score is approximately 0.047%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Attack complexity is rated High, as exploitation requires either backend access or a specific buyer-controlled field configuration (Feedly).
{invoice_company} in email subject templates.{{event.__init__.__code__.co_filename}} or {{event.__init__.__globals__}} into an email template subject or body.invoice_company field to a malicious placeholder string (e.g., {{event.__init__.__code__.co_filename}}). If the target's email subject template includes {invoice_company} and double-evaluation is present, the injected placeholder will be rendered in the outgoing email, disclosing sensitive data (Feedly, pretix Blog).__init__, __code__, __globals__, co_filename) in subject or body fields.pretix.cfg values or API keys appearing in email logs or sent message archives.{{...}} double-brace expressions.invoice_company field contains placeholder syntax (e.g., {{event.*}}) rather than a legitimate company name.Upgrade pretix to version 2026.1.1 or later, which contains fixes for both the incomplete placeholder sanitization in email subjects and the double-evaluation logic flaw (pretix Blog). As an immediate precaution, rotate all passwords and API keys stored in pretix.cfg, as these may have been exposed if the system ran a vulnerable version. Restrict email template editing permissions to trusted administrators only, and audit existing email templates for any suspicious placeholder expressions containing Python attribute traversal syntax. No configuration-only workaround fully mitigates the vulnerability without upgrading.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."