CVE-2026-27641 is a critical vulnerability in Flask-Reuploaded affecting versions prior to 1.5.0. The flaw allows attacker-controlled file upload paths and filenames to bypass intended safety controls, resulting in path traversal and extension validation bypass during file handling. By abusing unsafe handling of the user-influenced name parameter, an attacker can cause arbitrary file write outside the intended upload directory. In deployments where the written file can later be interpreted as a server-side template or executable application content, the arbitrary write can be chained into Server-Side Template Injection and remote code execution. The issue is rooted in insufficient restriction of attacker-controlled path components and inadequate enforcement of upload filename and extension policy.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
name parameter and use auto-generated filenames only. If custom naming is unavoidable, strictly sanitize and validate the supplied name, strip path separators and traversal sequences, reduce to a safe basename, and enforce a strict allowlist of permitted extensions before saving. Store uploaded files outside web-served and execution-capable directories, and disable server-side execution or template rendering of uploaded content wherever possible.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept for CVE-2026-27641 affecting Flask-Reuploaded versions prior to 1.5.0. It contains two Python files and a README. PoC.py is the main exploit script: it accepts a target upload URL, a filename, and file content; optionally reads content from stdin when --content is '-', checks connectivity by issuing a GET request to the target root, then sends a multipart/form-data POST to the supplied upload endpoint using requests.post(..., files={"file": (name, content)}). The exploit capability is arbitrary file write via attacker-controlled filename/path traversal, as suggested by the README and the --name help text example '../..//test.txt'. vuln_server.py is a local vulnerable demo server built with Flask and flask_uploads; it exposes '/' returning 200 and '/file_uploads' accepting POST uploads, then calls files.save(fichier, name=fichier.filename), demonstrating the unsafe handling path. The repository purpose is clearly to demonstrate and reproduce the vulnerability rather than provide stealth, persistence, or post-exploitation features. No hardcoded external IPs or domains are present; endpoints are local/application-relative and user-supplied at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.