CVE-2026-27641: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27641 is a critical path traversal and Server-Side Template Injection (SSTI) vulnerability in Flask-Reuploaded, a file upload extension for Flask. It affects all versions prior to 1.5.0 and allows unauthenticated remote attackers to write arbitrary files to the server and achieve remote code execution. The vulnerability was discovered by Jaron Cabral (Cal Poly Humboldt), reported to the maintainer, and patched on February 21, 2026, with the advisory published on February 23–25, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Github Advisory, Security Advisory).

Technical details

The root cause lies in the save() method of Flask-Reuploaded's UploadSet class, which accepted unsanitized user input via the name parameter without applying secure_filename(), path containment checks, or post-override extension re-validation (CWE-22, CWE-1336). An attacker could supply a crafted name value containing path traversal sequences (e.g., ../templates/rce.html) to write files outside the intended upload directory, including into Flask's Jinja2 template directories. Once a malicious template file is written to a location served by the application, a subsequent HTTP request triggering template rendering results in SSTI and arbitrary code execution. The fix (commit d64c6b2) applies secure_filename() to both the name and extracted folder components, re-validates the file extension after any name override, and enforces os.path.realpath()-based path containment checks (Security Advisory, Fix Commit).

Impact

Successful exploitation grants a remote, unauthenticated attacker full control over the affected server. The attacker can write arbitrary files to any filesystem location accessible by the web process — including Flask template directories — enabling remote code execution via SSTI, exfiltration of sensitive data (credentials, configuration files, secrets), modification or deletion of critical files, and potential lateral movement within the hosting environment. All three security pillars — confidentiality, integrity, and availability — are rated High (Github Advisory).

Exploitability

No public proof-of-concept exploit code has been identified as of the time of this report, and there is no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.146–0.226%, placing it in the 45th percentile for exploitation likelihood within 30 days. No threat actor attribution is available, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no user interaction, and low complexity, making it highly attractive if a working exploit is developed and published.

Exploitation steps

  1. Reconnaissance: Identify Flask applications using Flask-Reuploaded versions prior to 1.5.0 by inspecting requirements.txt, pyproject.toml, or package metadata exposed via error pages or public repositories.
  2. Locate file upload endpoint: Find an endpoint that calls UploadSet.save() and passes user-controlled input to the name parameter (e.g., a form field like custom_name).
  3. Craft path traversal payload: Submit a multipart file upload request with a malicious name value such as ../templates/rce.html, targeting Flask's Jinja2 template directory relative to the upload destination.
  4. Inject SSTI payload: Embed a Jinja2 template expression in the uploaded file content, for example: {{ config.__class__.__init__.__globals__['os'].popen('id').read() }}.
  5. Trigger template rendering: Send an HTTP request to any Flask route that renders the now-malicious template (e.g., a route that renders rce.html), causing the Jinja2 engine to evaluate the injected expression and execute arbitrary OS commands.
  6. Achieve RCE: Collect command output from the HTTP response or establish a reverse shell for persistent access (Security Advisory, Fix Commit).

Indicators of compromise

  • Network: Multipart POST requests to file upload endpoints where the name form field contains path traversal sequences (../, ..\, /etc/, /tmp/) or Jinja2 template syntax ({{, }}); unexpected outbound connections from the web server process.
  • File System: Unexpected .html, .jinja2, or script files appearing in Flask template directories or outside the configured upload destination; files with names containing Jinja2 expressions or shell commands in their content.
  • Logs: Web server access logs showing POST requests to upload endpoints with encoded or raw path traversal strings in form parameters; application error logs showing Jinja2 TemplateNotFound or unexpected template rendering errors shortly after an upload.
  • Process: Unusual child processes spawned by the Python/Flask web process (e.g., sh, bash, curl, wget, python) following a file upload request; unexpected network connections initiated by the web application process.

Mitigation and workarounds

Upgrade Flask-Reuploaded to version 1.5.0 immediately, as this release applies secure_filename() to the name and folder parameters, re-validates extensions after name overrides, and enforces path containment using os.path.realpath() (Github Advisory, Fix PR). For applications that cannot upgrade immediately, apply the following workarounds: (1) do not pass user-controlled input to the name parameter — use auto-generated filenames only; (2) if name must accept user input, sanitize it with werkzeug.utils.secure_filename() and os.path.basename() before passing it to save(); (3) validate that the resulting file extension matches the allowed policy before saving.

Community reactions

The vulnerability received coverage from The Hacker Wire and security community aggregators shortly after disclosure (The Hacker Wire). Discussion was noted on Mastodon and Bluesky within hours of the advisory publication. Red Hat also tracked the vulnerability for potential impact on their ecosystem (Red Hat CVE). Community sentiment highlighted the severity of the unauthenticated RCE vector and the straightforward nature of the fix.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management