CVE Feed

    Dashboard / CVE / CVE-2026-27641

    CVE-2026-27641

    Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter, use auto-generated filenames only, and implement strict input validation if `name` must be used.

    Published:Feb 25, 2026
    Last Modified:Apr 17, 2026
    EPS:Feb 25, 2026
    EPSS Score:0.00216
    CVSS Score:9.8

    Affected Products

    Vendor
    Jugmac00
    Product
    Flask-reuploaded

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High