CWE-1336Base2 in KEV

Improper Neutralization of Special Elements Used in a Template Engine

Incomplete in the CWE catalog · 224 CVEs mapped

224
CVEs mapped
2
In KEV
8.3
Median CVSS
What it is

The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Recent examples
none
CVE-2026-46636

CVE-2026-46636 - UNKNOWN Severity Vulnerability

Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.

no explanation yet
0%
epss
7.8cvss
CVE-2026-85654

CVE-2026-85654 - HIGH Severity Vulnerability

Improper neutralization of special elements used in a template engine in the CDK generator in Amazon awslabs.dynamodb-mcp-server before 2.1.6 might allow a context-dependent actor to execute arbitrary code on the host that deploys the generated application via crafted table, index, or attribute names in a data model file.

HIGHno explanation yet
0%
epss
none
CVE-2026-13297

CVE-2026-13297 - UNKNOWN Severity Vulnerability

IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-1336
Abstraction
Base
Structure
Simple
Status
Incomplete
References (2)