CVE-2026-2451Patch(pretix / double_opt_in_step)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pretix double_opt_in_step systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. This mechanism contained a security-relevant bug: It was possible to exfiltrate information about the pretix system through specially crafted placeholder names such as {{event.__init__.__code__.co_filename}}. This way, an attacker with the ability to control email templates (usually every user of the pretix backend) could retrieve sensitive information from the system configuration, including even database passwords or API keys. pretix does include mechanisms to prevent the usage of such malicious placeholders, however due to a mistake in the code, they were not fully effective for this plugin. Out of caution, we recommend that you rotate all passwords and API keys contained in your pretix.cfg file.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-627

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • double_opt_in_step
  • pretix

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
double_opt_in_steppretix

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-17: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-17: 102-17
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
Full discourse1 post
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 HIGH severity alert: pretix-doistep 1.0.0 lets backend users exploit email placeholders to leak sensitive config, passwords & API keys. Rotate creds & restrict template edits now! 🔒 https://radar.offseq.com/threat/cve-2026-2451-cwe-627-dynamic-variable-evaluation--3e2879f1 #... https://t.co/JlhwnPIUna

    Post summary

    High‑severity CVE‑2026‑2451 in pretix‑doistep 1.0.0 allows backend users to use email placeholders to expose sensitive data; immediate credential rotation and restriction of template edits are advised.

    0000046
    265 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppretixdouble_opt_in_step-pretix-
Apppretixpretix---

Explore more