CVE-2026-5559: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-5559 is a Server-Side Template Injection (SSTI) / Remote Code Execution (RCE) vulnerability in AntaresMugisho PyBlade, a lightweight Python template engine for Django. The flaw resides in the _is_safe_ast() function within sandbox.py, which fails to properly neutralize special elements used in template expressions, allowing authenticated remote attackers to inject and execute arbitrary Python code. Affected versions are 0.1.8-alpha and 0.1.9-alpha (CVE scope per VulDB), with the broader issue also impacting 0.2.0-alpha via a separate eval() misuse. It was disclosed publicly on April 5, 2026, with a CVSS v3.1 score of 6.3 (Medium) and a CVSS v4.0 score of 2.1 (Low) (Github Advisory, PyBlade Issue).

Technical details

The root cause is classified under CWE-791 (Incomplete Filtering of Special Elements) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). In versions 0.1.8-alpha and 0.1.9-alpha, the _is_safe_ast() function in sandbox.py only validates ast.Name nodes during attribute access checks, but fails to validate ast.Constant nodes — meaning expressions like ''.__class__ (where '' is a string constant) bypass the whitelist entirely and allow traversal of Python's object model via __class__, __mro__, and __subclasses__(). In v0.2.0-alpha, the issue is more severe: evaluator.py calls eval() directly with no AST validation at all. A proof-of-concept exploit was publicly disclosed in the GitHub issue report by researcher JasonZhang1996 on March 17, 2026 (PyBlade Issue).

Impact

Successful exploitation allows an authenticated attacker with low privileges to achieve Remote Code Execution on the server hosting the PyBlade template engine. By traversing Python's object model, an attacker can execute arbitrary OS commands (e.g., via os.popen()), potentially leading to full system compromise, unauthorized data disclosure, data manipulation, and service disruption. The scope is limited to the vulnerable system itself (no subsequent system impact), but RCE capability enables lateral movement, credential theft, and persistent access (Github Advisory, PyBlade Issue).

Exploitability

A proof-of-concept exploit was publicly disclosed in the GitHub issue tracker on March 17, 2026, and is freely available. The EPSS score is approximately 0.052% (0.022% per GitHub Advisory), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires low-privilege authenticated access but no user interaction, and attack complexity is low (Github Advisory, PyBlade Issue).

Exploitation steps

  1. Reconnaissance: Identify applications using PyBlade versions 0.1.8-alpha, 0.1.9-alpha, or 0.2.0-alpha as their template engine. Look for Django applications with PyBlade installed via pip show pyblade.
  2. Obtain low-privilege access: Authenticate to the target application with any valid low-privilege user account that can submit or influence template content rendered by PyBlade.
  3. Craft SSTI payload (v0.1.8/0.1.9-alpha): Inject a template expression using a string constant to bypass the ast.Name-only whitelist check. Start with enumeration: {{ ''.__class__.__mro__[1].__subclasses__() }} to list available Python subclasses.
  4. Identify the target subclass index: From the returned subclass list, identify the index of a useful class (e.g., a class with access to os or subprocess modules — commonly around index 228 for os-accessible classes, though this varies by environment).
  5. Execute OS commands: Use the identified index to execute arbitrary commands: {{ ''.__class__.__mro__[1].__subclasses__()[228].__init__.__globals__['sys'].modules['os'].popen('whoami').read() }}
  6. Escalate: Use command execution to establish a reverse shell, exfiltrate credentials, or pivot to other systems (PyBlade Issue).

Indicators of compromise

  • Logs: Web application logs showing template rendering requests containing Python dunder attributes such as __class__, __mro__, __subclasses__, __init__, or __globals__ in template input fields or URL parameters.
  • Logs: Application error logs showing unexpected Python object introspection output or os.popen execution traces from the PyBlade rendering engine.
  • Process: Unusual child processes spawned by the Python/Django web server process (e.g., sh, bash, curl, wget, python) that are not part of normal application behavior.
  • Network: Unexpected outbound connections from the web server to external IPs, particularly on non-standard ports, following template rendering requests.
  • File System: New files written to the web server's working directory or /tmp by the web application process, including scripts, reverse shell payloads, or credential dumps (PyBlade Issue).

Mitigation and workarounds

The vulnerability has been fixed in the latest main branch of PyBlade via commit 62c95c47 (2026-02-24), which introduces an AST-based SafeEvaluator class that properly validates all AST node types (including ast.Constant), blocks access to private attributes (those starting with _), and restricts method calls to a whitelist. Users running versions 0.1.8-alpha, 0.1.9-alpha, or 0.2.0-alpha should upgrade to the patched version immediately. As a temporary workaround, restrict network access to PyBlade installations, limit user privileges for template processing, and monitor template rendering activity for suspicious patterns (Github Advisory, PyBlade Issue).

Community reactions

The vulnerability was reported by researcher JasonZhang1996 via a GitHub issue on March 17, 2026, with a detailed technical write-up and working proof-of-concept. As of the advisory publication date, the PyBlade project maintainer had not publicly responded to the issue report. The GitHub Advisory Database classified the severity as Low (CVSS v4.0: 2.1), while VulDB and NVD assigned a Medium score (CVSS v3.1: 6.3), reflecting differing assessment of the RCE potential. Coverage was picked up by automated vulnerability tracking services including VulDB, INCIBE-CERT, and ENISA's EUVD (Github Advisory, PyBlade Issue).

Additional resources

  • Github Advisory — GHSA-23jg-5f8m-gw8c advisory with CVSS details and patch reference
  • PyBlade Issue — Original researcher disclosure with PoC exploit code
  • PyBlade Repo — Official PyBlade source repository and patched main branch
  • VulDB Entry — VulDB vulnerability database entry
  • ENISA EUVD — European Union Vulnerability Database entry

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management