CVE-2025-3841 is a critical vulnerability affecting wix-incubator jam up to version e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This flaw, located in the Jinja2 Template Handler component, specifically within the jam.py file, allows for improper neutralization of special elements in a template engine through manipulation of the 'config['template']' argument. With a CVSS score of 9.8 (CRITICAL), this vulnerability is remotely exploitable with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While the exploit has been publicly disclosed, there is currently no evidence of active exploitation, nor are there Metasploit or Nuclei modules available, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2018-03-27CPE matchmatch criteria | cpe:2.3:a:wix:jam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.