Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE
CVE-2025-23211
Verified
Description
Tandoor Recipes < 1.5.24 has a Jinja2 SSTI vulnerability that allows command execution via recipe steps.
Severity
Critical
CVSS Score
9.9
Exploit Probability
4%
Published Date
July 27, 2025
Template Author
sammiee5311
CVE-2025-23211.yaml
9.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-23211
CWE ID:
cwe-94, cwe-1336
References
https://github.com/TandoorRecipes/recipes/blob/4f9bff20c858180d0f7376de443a9fe4c123a50c/cookbook/helper/template_helper.py#L95https://github.com/TandoorRecipes/recipes/commit/e6087d5129cc9d0c24278948872377e66c2a2c20https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-r6rj-h75w-vj8vhttps://nvd.nist.gov/vuln/detail/CVE-2025-23211
Remediation Steps
Upgrade to Tandoor Recipes version 1.5.24 or later.