GHSA-jc7g-x28f-3v3h
CRITICALCVE-2025-49136The env and expandenv template functions which is enabled by default in [Sprig](https://masterminds.github.io/sprig/) enables capturing of env variables on the host. While this may not be a problem on single-user (super admin) installations, on multi-user installations, this allows non-super-admin users with campaign or template permissions to use the {{ env }} template expression to capture sensi
- Affected
- >=0
- Fixed in
- 5.0.2
- Weakness
- CWE-1336
- Published
- 2025-06-09
- Source
- github