Skip to content

High-severity vulnerabilities issues related to Jinja2 #1091

@svor

Description

@svor

There are two high-severity vulnerabilities affecting Jinja2, which appears to be bundled at build time under the following path in the repository:

📁 robotframework-ls/src/robotframework_ls/vendored

⚠️ Affected CVEs:
CVE-2024-56201

CVE-2024-56326

These vulnerabilities may expose users to code execution risks or template injection attacks, depending on how Jinja2 is used internally.

✅ Recommended Action:
To address these issues, upgrade Jinja2 to version 3.1.5 or later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions