CVE-2026-33154

dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side Template Injection (SSTI) due to unsafe template evaluation in the @Jinja resolver. When the jinja2 package is installed, Dynaconf evaluates template expressions embedded in configuration values without a sandboxed environment. This issue has been patched in version 3.2.13.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dynaconf:dynaconf:*:*:*:*:*:*:*:*

History

14 Apr 2026, 18:23

Type Values Removed Values Added
References () https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7 - () https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7 - Patch
References () https://github.com/dynaconf/dynaconf/releases/tag/3.2.13 - () https://github.com/dynaconf/dynaconf/releases/tag/3.2.13 - Release Notes
References () https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p - () https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p - Exploit, Vendor Advisory
CWE CWE-78
Summary
  • (es) dynaconf es una herramienta de gestión de configuración para Python. Antes de la versión 3.2.13, Dynaconf es vulnerable a la Inyección de Plantilla del Lado del Servidor (SSTI) debido a la evaluación insegura de plantillas en el resolvedor @Jinja. Cuando el paquete jinja2 está instalado, Dynaconf evalúa expresiones de plantilla incrustadas en valores de configuración sin un entorno aislado. Este problema ha sido parcheado en la versión 3.2.13.
CPE cpe:2.3:a:dynaconf:dynaconf:*:*:*:*:*:*:*:*
First Time Dynaconf
Dynaconf dynaconf

20 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 21:17

Updated : 2026-04-14 18:23


NVD link : CVE-2026-33154

Mitre link : CVE-2026-33154

CVE.ORG link : CVE-2026-33154


JSON object : View

Products Affected

dynaconf

  • dynaconf
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')