On Wed Aug 19, 2026 at 1:15 PM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Hetvi Thakar <[email protected]>
>
> This patch applies the upstream fix as referenced in [2], using
> the commit shown in [1].
>
> The backport makes Template URI normalization strip all leading
> slashes, preventing a double-slash URI from bypassing the path
> traversal check while keeping Mako at version 1.3.2.
>
> [1] 
> https://github.com/sqlalchemy/mako/commit/e05ac61989a7fb9dd7dcde6cfd72dc48328719a3
> [2] https://github.com/advisories/GHSA-v92g-xgxw-vvmm
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
>  .../python/python3-mako/CVE-2026-41205.patch  | 110 ++++++++++++++++++
>  .../python/python3-mako_1.3.2.bb              |   2 +
>  2 files changed, 112 insertions(+)
>  create mode 100644 
> meta/recipes-devtools/python/python3-mako/CVE-2026-41205.patch

Hello,

As fas as I can tell, a fix for this CVE is also needed on wrynose.

I can't merge here until this is fixed there.

Can you send a patch to fix this and then, ping back here?

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#244754): 
https://lists.openembedded.org/g/openembedded-core/message/244754
Mute This Topic: https://lists.openembedded.org/mt/120827665/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org
      • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
        • ... Yoann Congal via lists.openembedded.org

Reply via email to