CVE-2026-102991
Deferred Deferred - Pending Action

Template Path Traversal in Mako Python Library

Vulnerability report for CVE-2026-102991, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Mako is a template library written in Python. Prior to 1.4.2, on Windows, TemplateLookup.get_template() in mako/lookup.py resolves template URIs with posixpath, while Template.__init__() in mako/template.py validates them with os.path, which uses ntpath. A URI beginning with a drive designator causes ntpath to absorb the traversal segments before the leading dot-dot check, while posixpath resolution can escape the configured template directory. An application that passes attacker-controlled template names or include paths can disclose process-readable files on the same volume, and a targeted file containing Mako template syntax may also be parsed and executed as a template. Raw URL paths are generally normalized before reaching this form, but query strings, form or JSON bodies, route parameters, and dynamic include expressions can preserve it. This issue is fixed in version 1.4.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mako mako to 1.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in Mako, a Python template engine, affecting Windows systems. It occurs due to inconsistent path handling between posixpath and ntpath modules. When a URI starts with a drive designator like C:/../../secret.txt, ntpath absorbs the traversal segments before security checks, while posixpath preserves them. This allows attackers to bypass directory restrictions and access files outside the template directory on the same volume. If the file contains Mako template syntax, it may also be executed as a template.

Detection Guidance

Check Mako version with pip show Mako. If version is below 1.4.2, the system is vulnerable. Review application logs for template paths containing drive designators like C:/ or C:\. Test with crafted URIs such as C:/../../secret.txt in template inputs.

Impact Analysis

An attacker could read any file accessible to the application process on the same volume as the template directory. If the file contains Mako or Python template syntax, it could be executed as a template, potentially leading to code execution. The attack can be performed remotely through query strings, form data, JSON bodies, route parameters, or template include directives without requiring privileges or user interaction.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. GDPR requires protection of personal data, while HIPAA mandates safeguards for protected health information. A successful exploit may result in data breaches, triggering compliance violations, legal penalties, and reputational damage for organizations handling regulated data.

Mitigation Strategies

Upgrade Mako to version 1.4.2 or later immediately. Audit all template inputs for drive designator patterns. Restrict file permissions to limit exposure. Monitor for unusual file access patterns in application logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102991. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart