Improper Neutralization of Special Elements Used in a Template Engine Affecting github.com/lxc/incus/internal/server/util package, versions <6.23.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.48% (38th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMLXCINCUSINTERNALSERVERUTIL-15812303
  • published30 Mar 2026
  • disclosed27 Mar 2026
  • creditgrmpyninja

Introduced: 27 Mar 2026

CVE-2026-33897  (opens in a new tab)
CWE-1336  (opens in a new tab)

How to fix?

Upgrade github.com/lxc/incus/internal/server/util to version 6.23.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine through improper implementation of the chroot isolation mechanism in the pongo2 template processing. An attacker can gain unauthorized access to read and write arbitrary files on the host system with root privileges by crafting malicious templates.

CVSS Base Scores

version 4.0
version 3.1