← Back to browse · API

CVE-2025-23211

Severity
CRITICAL
CVSS
10.0
EPSS
0.03524
Risk score
41.23
CISA KEV
No
PoC
No
Published
2025-01-28
Modified
2025-01-28
First seen
2026-08-07
Aliases
EUVD-2025-3143
Products
TandoorRecipes:Recipes < 1.5.24
Sources
euvd EUVD-2025-3143

Description

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

References