GHSA-2mf3-mr2r-r4vf
HIGH@rhinostone/swig is a maintained fork of the abandoned swig template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The {% include %}, {% extends %}, and {% import %} tags resolve their target path through the filesystem loader without confining the result to the configured template root. A path that traverses upward (../) escap
- Affected
- >=0, <2.7.1, < 2.7.1
- Fixed in
- 2.7.1
- Weakness
- CWE-22
- Published
- 2026-08-18
- Source
- osv