GHSA-65mp-fq8v-56jr
CRITICALCVE-2026-27641A critical path traversal and extension bypass vulnerability in Flask-Reuploaded allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).
- Affected
- < 1.5.0
- Fixed in
- 1.5.0
- Weakness
- CWE-22
- Published
- 2026-02-25
- Source
- github