CVE-2026-27641Disclosure(jugmac00 / flask-reuploaded)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jugmac00 flask-reuploaded systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0. Some workarounds are available. Do not pass user input to the `name` parameter, use auto-generated filenames only, and implement strict input validation if `name` must be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flask-reuploaded

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 7 mentions (2026-02-25); latest day: 1
  • 8 total mentions across 2 days

Affected systems

Vendors
Products
flask-reuploaded

Deep dive

Activity timeline8 mentions / 2d
02457Mentions · 2026-02-25: 7Mentions · 2026-03-02: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-25: 6Technical Details · 2026-03-02: 102-2503-02
Signal classification3 categories
Disclosure
562.5%
General
225.0%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-257
Disclosure5General1Patch1
2026-03-021
General1
Full discourse8 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical path traversal and extension bypass vulnerability in #Flask-Re-uploaded. CVE-2026-27641 CVSS: 9.8. A remote attacker could exploit this to achieve arbitrary file write and remote code execution through server-side template injection. #RCE! #Patch #Patch #Patch

    Post summary

    A critical path traversal and extension bypass vulnerability (CVE-2026-27641) in Flask‑Re‑uploaded allows remote code execution via server‑side template injection, with a CVSS score of 9.8.

    10020193
    7.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27641 Path Traversal and SSTI in Flask-Reuploaded Versions Before 1.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27641 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new vulnerability (CVE-2026-27641) affecting Flask‑Reuploaded before version 1.5.0 has been disclosed, involving path traversal and SSTI issues.

    0001038
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27641 (CVSS:9.8, CRITICAL) is Analyzed. Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versio..https://nvd.nist.gov/vuln/detail/CVE-2026-27641 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet highlights CVE-2026-27641’s critical CVSS score and path traversal/extension bypass flaw in Flask‑Reuploaded, but offers no PoC, exploit, patch, or evidence of active exploitation.

    0000037
    173 followersView on X
  • Michael → building chrome extensions #21 of 100@_alphashark_
    General

    @CCBalert The truth is, vulnerabilities like CVE-2026-27641 remind us that security isnt an afterthoughtits a necessity. Every line of code is a potential entry point. Stay vigilant and patch early. Your softwares integrity depends on it.

    Post summary

    The post references CVE-2026-27641 as a reminder to stay vigilant and patch, but offers no technical details, PoC, or evidence of exploitation.

    0000025
    3.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27641 Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to a… https://www.cve.org/CVERecord?id=CVE-2026-27641

    Post summary

    CVE‑2026‑27641 is a path traversal and extension bypass flaw in Flask‑Reuploaded versions before 1.5.0, potentially allowing remote attackers to exploit the vulnerability.

    0000099
    56.6K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: flask-reuploaded < 1.5.0 has a 9.8 CVSS SSTI flaw! Remote code execution & arbitrary file writes possible — no auth needed. Upgrade ASAP & sanitize input. Details: https://radar.offseq.com/threat/cve-2026-27641-cwe-1336-improper-neutralization-of-693604e2 #OffSeq #... https://t.co/n6fno0izXC

    Post summary

    Critical SSTI flaw in flask-reuploaded <1.5.0 allows unauthenticated remote code execution and arbitrary file writes; patch immediately.

    0000039
    270 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27641: CRITICAL] Flask-Reuploaded vulnerability patched! Upgrade to version 1.5.0 now to prevent remote attacks through Server-Side Template Injection. Follow workarounds for temporary protection.#cve,CVE-2026-27641,#cybersecurity https://cvefind.com/CVE-2026-27641

    Post summary

    The post announces that CVE‑2026‑27641 has been patched in Flask‑Reuploaded 1.5.0 and advises upgrading and applying temporary workarounds to mitigate remote server‑side template injection attacks.

    0000051
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27641** pertains to the Flask-Reuploaded library, a package that facilitates file uploads in Flask applications. The vulnerability involves a **path traversal** and **extension bypass** flaw present in versions prior to 1.5.0. Exploiting this flaw allows remote attackers to perform **arbitrary file writes** and **remote code execution (RCE)** via **Server-Side Template Injection (SSTI)**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27641

    Post summary

    CVE-2026-27641 is a path traversal and SSTI flaw in Flask‑Reuploaded that enables arbitrary file writes and remote code execution in versions prior to 1.5.0.

    0000041
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjugmac00flask-reuploaded-python-

Explore more