{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@rhinostone/swig-django/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:swig-templates_project:swig-templates:*:*:*:*:*:*:*:*","cpe:2.3:a:swig_project:swig:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2023-25345"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@rhinostone/swig","@rhinostone/swig-core","@rhinostone/swig-twig","@rhinostone/swig-jinja2","@rhinostone/swig-django"],"_cs_severities":["high"],"_cs_tags":["directory-traversal","arbitrary-file-read","template-injection","cve-2023-25345"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe \u003ccode\u003e@rhinostone/swig\u003c/code\u003e package, a maintained fork of the legacy \u003ccode\u003eswig\u003c/code\u003e template engine, inherits a path traversal vulnerability originally documented as CVE-2023-25345. The vulnerability manifests within the filesystem loader's handling of \u003ccode\u003e{% include %}\u003c/code\u003e, \u003ccode\u003e{% extends %}\u003c/code\u003e, and \u003ccode\u003e{% import %}\u003c/code\u003e tags. When processing these tags, the engine fails to validate that the requested template path remains within the defined template root directory.\u003c/p\u003e\n\u003cp\u003eAn attacker who can influence the path string, either through application logic that maps user-supplied data to template variables or by exploiting direct template manipulation, can insert traversal sequences like \u003ccode\u003e../\u003c/code\u003e to escape the root directory. This allows the reading of sensitive host files, such as \u003ccode\u003e/etc/passwd\u003c/code\u003e or application configuration files, which are subsequently returned in the rendered HTTP response. The flaw affects the primary \u003ccode\u003e@rhinostone/swig\u003c/code\u003e package and its core loader component, as well as several derivative engines including \u003ccode\u003eswig-twig\u003c/code\u003e, \u003ccode\u003eswig-jinja2\u003c/code\u003e, and \u003ccode\u003eswig-django\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary local file disclosure. Depending on the server's permissions, this enables the exfiltration of critical information including application source code, database credentials, environment variables, and system-level configuration files. The impact is primarily on the confidentiality of the application and the host server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update \u003ccode\u003e@rhinostone/swig\u003c/code\u003e and related packages to version \u003ccode\u003e2.7.2\u003c/code\u003e or later to mitigate CVE-2023-25345 while avoiding the regression introduced in \u003ccode\u003e2.7.1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit application code for any instances where user-supplied input is directly passed as a variable into template include/extends tags.\u003c/li\u003e\n\u003cli\u003eConfigure the filesystem loader with an explicit and restrictive basepath if an immediate update is not feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T21:00:02Z","date_published":"2026-08-18T21:00:02Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rhinostone-swig-traversal/","summary":"The @rhinostone/swig template engine (CVE-2023-25345) contains a path traversal vulnerability in its filesystem loader, allowing unauthenticated attackers to read arbitrary local files via include or extends tags.","title":"Path Traversal in @rhinostone/swig Template Engine","url":"https://feed.craftedsignal.io/briefs/2026-08-rhinostone-swig-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - @Rhinostone/Swig-Django","version":"https://jsonfeed.org/version/1.1"}