CVE-2025-23211Disclosure(tandoor / recipes)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • recipes

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
recipes

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-21: 1Technical Details · 2026-04-21: 104-21
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-23211 - critical 🚨 Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCE > Tandoor Recipes < 1.5.24 has a Jinja2 SSTI vulnerability that allows command executio... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-23211 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE‑2025‑23211 as a critical Jinja2 SSTI RCE affecting Tandoor Recipes < 1.5.24, providing only vulnerability type details without PoC, exploit, or patch information.

    00020337
    942 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptandoorrecipes---

Explore more