CVE-2026-33154 identifies a Server-Side Template Injection (SSTI) vulnerability in dynaconf, a Python configuration management tool, affecting versions prior to 3.2.13, due to unsafe template evaluation in its @Jinja resolver. Rated 7.5 HIGH, this flaw has a high attack complexity but allows a low-privileged attacker to achieve high impact on confidentiality, integrity, and availability via network access. Currently, there is no evidence of active exploitation, nor are public exploit modules available, indicating a low immediate exploitation risk and limited community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.13CPE matchmatch criteria | cpe:2.3:a:dynaconf:dynaconf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.