
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27641 is a critical path traversal and Server-Side Template Injection (SSTI) vulnerability in Flask-Reuploaded, a file upload extension for Flask. It affects all versions prior to 1.5.0 and allows unauthenticated remote attackers to write arbitrary files to the server and achieve remote code execution. The vulnerability was discovered by Jaron Cabral (Cal Poly Humboldt), reported to the maintainer, and patched on February 21, 2026, with the advisory published on February 23–25, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Github Advisory, Security Advisory).
The root cause lies in the save() method of Flask-Reuploaded's UploadSet class, which accepted unsanitized user input via the name parameter without applying secure_filename(), path containment checks, or post-override extension re-validation (CWE-22, CWE-1336). An attacker could supply a crafted name value containing path traversal sequences (e.g., ../templates/rce.html) to write files outside the intended upload directory, including into Flask's Jinja2 template directories. Once a malicious template file is written to a location served by the application, a subsequent HTTP request triggering template rendering results in SSTI and arbitrary code execution. The fix (commit d64c6b2) applies secure_filename() to both the name and extracted folder components, re-validates the file extension after any name override, and enforces os.path.realpath()-based path containment checks (Security Advisory, Fix Commit).
Successful exploitation grants a remote, unauthenticated attacker full control over the affected server. The attacker can write arbitrary files to any filesystem location accessible by the web process — including Flask template directories — enabling remote code execution via SSTI, exfiltration of sensitive data (credentials, configuration files, secrets), modification or deletion of critical files, and potential lateral movement within the hosting environment. All three security pillars — confidentiality, integrity, and availability — are rated High (Github Advisory).
No public proof-of-concept exploit code has been identified as of the time of this report, and there is no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.146–0.226%, placing it in the 45th percentile for exploitation likelihood within 30 days. No threat actor attribution is available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and low complexity, making it highly attractive if a working exploit is developed and published.
requirements.txt, pyproject.toml, or package metadata exposed via error pages or public repositories.UploadSet.save() and passes user-controlled input to the name parameter (e.g., a form field like custom_name).name value such as ../templates/rce.html, targeting Flask's Jinja2 template directory relative to the upload destination.{{ config.__class__.__init__.__globals__['os'].popen('id').read() }}.rce.html), causing the Jinja2 engine to evaluate the injected expression and execute arbitrary OS commands.name form field contains path traversal sequences (../, ..\, /etc/, /tmp/) or Jinja2 template syntax ({{, }}); unexpected outbound connections from the web server process..html, .jinja2, or script files appearing in Flask template directories or outside the configured upload destination; files with names containing Jinja2 expressions or shell commands in their content.TemplateNotFound or unexpected template rendering errors shortly after an upload.sh, bash, curl, wget, python) following a file upload request; unexpected network connections initiated by the web application process.Upgrade Flask-Reuploaded to version 1.5.0 immediately, as this release applies secure_filename() to the name and folder parameters, re-validates extensions after name overrides, and enforces path containment using os.path.realpath() (Github Advisory, Fix PR). For applications that cannot upgrade immediately, apply the following workarounds: (1) do not pass user-controlled input to the name parameter — use auto-generated filenames only; (2) if name must accept user input, sanitize it with werkzeug.utils.secure_filename() and os.path.basename() before passing it to save(); (3) validate that the resulting file extension matches the allowed policy before saving.
The vulnerability received coverage from The Hacker Wire and security community aggregators shortly after disclosure (The Hacker Wire). Discussion was noted on Mastodon and Bluesky within hours of the advisory publication. Red Hat also tracked the vulnerability for potential impact on their ecosystem (Red Hat CVE). Community sentiment highlighted the severity of the unauthenticated RCE vector and the straightforward nature of the fix.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."