Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Brecht — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting Brecht. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Brecht is a Python templating engine primarily used for generating dynamic web content and email templates. Historically, it has been vulnerable to remote code execution (RCE) due to unsafe template evaluation, cross-site scripting (XSS) from improper output escaping, and privilege escalation through insecure context handling. The project has recorded six CVEs, with notable issues including sandbox bypasses and unsafe deserialization. While no major public incidents have been widely reported, the consistent pattern of RCE vulnerabilities in templating engines like Brecht highlights the risks of dynamic code execution in web applications. Security researchers have emphasized the importance of proper input validation and sandboxing when using such templating systems.

This page lists every published CVE security advisory associated with Brecht. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.