CVE-2026-33154
dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
- Dynaconf
- < 3.2.13
- Fix
- Available
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 0.5% (43th percentile)
- Weakness
- CWE-94, CWE-1336, CWE-78
- NVD status
- Analyzed
- Published
- 2026-03-20
CVE-2026-33154 at NVD
1 known exploit for CVE-2026-33154
Proof-of-concept code and exploit modules indexed by Sploitus