StackRadar

CVE-2024-56201

High

Advisory

Published 23 Dec 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
251
of 17,781 indexed, latest versions
Container images
256
deployed by those charts
Fix available
3 of 3
affected packages

Jinja has a sandbox breakout through malicious filenames

Carried by container images the latest versions of 251 of 17,781 indexed charts deploy, on 256 images.

Affected packageAffected versionsFixed inImages
jinja2pypi3.0.0, 3.0.1, 3.0.2, 3.0.3+5 more3.1.5249
jinja2deb2.7.2-2, 2.10.1-2, 3.0.3-1, 3.0.3-1ubuntu0.1+1 more2.7.2-2ubuntu0.1~esm6, 2.10.1-2ubuntu0.4, 3.0.3-1ubuntu0.313
py3-jinja2apk3.1.2-r23.1.5-r01
OSV records
ALPINE-CVE-2024-56201GHSA-gmj6-6f8f-6699UBUNTU-CVE-2024-56201
Also known as
PYSEC-2026-1472, USN-7244-1, USN-7343-1

Charts affected

251 by stars
ChartLatestAffected imagesRadar Score
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-56201.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
jinja2@3.1.2
3.1.5

Open the chart page →

5,846

Container images carrying it

256 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
jinja2@3.1.2
3.1.5
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
jinja2@3.1.3
3.1.5
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
jinja2@3.1.2
3.1.5
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
jinja2@3.1.4
3.1.5
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
jinja2@3.1.2
3.1.5
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
jinja2@3.1.2
3.1.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.