
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5559 is a Server-Side Template Injection (SSTI) / Remote Code Execution (RCE) vulnerability in AntaresMugisho PyBlade, a lightweight Python template engine for Django. The flaw resides in the _is_safe_ast() function within sandbox.py, which fails to properly neutralize special elements used in template expressions, allowing authenticated remote attackers to inject and execute arbitrary Python code. Affected versions are 0.1.8-alpha and 0.1.9-alpha (CVE scope per VulDB), with the broader issue also impacting 0.2.0-alpha via a separate eval() misuse. It was disclosed publicly on April 5, 2026, with a CVSS v3.1 score of 6.3 (Medium) and a CVSS v4.0 score of 2.1 (Low) (Github Advisory, PyBlade Issue).
The root cause is classified under CWE-791 (Incomplete Filtering of Special Elements) and CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). In versions 0.1.8-alpha and 0.1.9-alpha, the _is_safe_ast() function in sandbox.py only validates ast.Name nodes during attribute access checks, but fails to validate ast.Constant nodes — meaning expressions like ''.__class__ (where '' is a string constant) bypass the whitelist entirely and allow traversal of Python's object model via __class__, __mro__, and __subclasses__(). In v0.2.0-alpha, the issue is more severe: evaluator.py calls eval() directly with no AST validation at all. A proof-of-concept exploit was publicly disclosed in the GitHub issue report by researcher JasonZhang1996 on March 17, 2026 (PyBlade Issue).
Successful exploitation allows an authenticated attacker with low privileges to achieve Remote Code Execution on the server hosting the PyBlade template engine. By traversing Python's object model, an attacker can execute arbitrary OS commands (e.g., via os.popen()), potentially leading to full system compromise, unauthorized data disclosure, data manipulation, and service disruption. The scope is limited to the vulnerable system itself (no subsequent system impact), but RCE capability enables lateral movement, credential theft, and persistent access (Github Advisory, PyBlade Issue).
A proof-of-concept exploit was publicly disclosed in the GitHub issue tracker on March 17, 2026, and is freely available. The EPSS score is approximately 0.052% (0.022% per GitHub Advisory), indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires low-privilege authenticated access but no user interaction, and attack complexity is low (Github Advisory, PyBlade Issue).
pip show pyblade.ast.Name-only whitelist check. Start with enumeration: {{ ''.__class__.__mro__[1].__subclasses__() }} to list available Python subclasses.os or subprocess modules — commonly around index 228 for os-accessible classes, though this varies by environment).{{ ''.__class__.__mro__[1].__subclasses__()[228].__init__.__globals__['sys'].modules['os'].popen('whoami').read() }}__class__, __mro__, __subclasses__, __init__, or __globals__ in template input fields or URL parameters.os.popen execution traces from the PyBlade rendering engine.sh, bash, curl, wget, python) that are not part of normal application behavior./tmp by the web application process, including scripts, reverse shell payloads, or credential dumps (PyBlade Issue).The vulnerability has been fixed in the latest main branch of PyBlade via commit 62c95c47 (2026-02-24), which introduces an AST-based SafeEvaluator class that properly validates all AST node types (including ast.Constant), blocks access to private attributes (those starting with _), and restricts method calls to a whitelist. Users running versions 0.1.8-alpha, 0.1.9-alpha, or 0.2.0-alpha should upgrade to the patched version immediately. As a temporary workaround, restrict network access to PyBlade installations, limit user privileges for template processing, and monitor template rendering activity for suspicious patterns (Github Advisory, PyBlade Issue).
The vulnerability was reported by researcher JasonZhang1996 via a GitHub issue on March 17, 2026, with a detailed technical write-up and working proof-of-concept. As of the advisory publication date, the PyBlade project maintainer had not publicly responded to the issue report. The GitHub Advisory Database classified the severity as Low (CVSS v4.0: 2.1), while VulDB and NVD assigned a Medium score (CVSS v3.1: 6.3), reflecting differing assessment of the RCE potential. Coverage was picked up by automated vulnerability tracking services including VulDB, INCIBE-CERT, and ENISA's EUVD (Github Advisory, PyBlade Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."