mako
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting makopage 1 of 1
- CVE-2010-2480NONECVSS 0.0EG 0.0✓ Fixed in 0.3.42010-07-02
vulnerable: 0.1.0 ... 0.3.3 (21 versions)
Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters a…
- CVE-2022-40023HIGHCVSS 7.5EG 7.5✓ Fixed in 1.2.22022-09-07
vulnerable: 0.1.0 ... 1.2.1 (63 versions)
Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.
- CVE-2026-41205HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.112026-04-23
vulnerable: 0.1.0 ... 1.3.9 (77 versions)
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stri…
- CVE-2026-44307HIGHCVSS 8.7EG 8.7✓ Fixed in 1.3.122026-05-12
vulnerable: 0.1.0 ... 1.3.9 (78 versions)
Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in Templ…
Check whether mako is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mako CVEs against the assets you own.
Start Free Scan →