Sploitus

CVE-2024-7093

No indexed exploits for CVE-2024-7093 yet

Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.

Affected products
Dispatch, Jinja
CVSS 4.0
9.4 CRITICAL
EPSS
0.5% (41th percentile)
Weakness
CWE-94
NVD status
Deferred
Published
2024-08-01
Attack patterns
CAPEC-248
CVE-2024-7093 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-7093 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-7093 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.