CVE-2025-3841 Details
Description
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation of the argument config['template'] leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
A server-side template injection vulnerability has been identified in Wix-Incubator Jam versions up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This vulnerability arises from improper validation and sanitization of user-provided template data in the Jinja2 template engine. Specifically, the issue is related to the 'config[template]' argument, which can be manipulated to inject malicious Jinja2 code. The vulnerability can be exploited locally, and an exploit is publicly available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/wix-incubator/jam/issues/1 | CISA-ADP | ExploitIssue TrackingVendor Advisory |
| https://github.com/wix-incubator/jam/issues/1 | [email protected] | ExploitIssue TrackingVendor Advisory |
| https://vuldb.com/?ctiid.305769 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.305769 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.555905 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
| CWE-791 | Incomplete Filtering of Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wix jam | < 2018-03-27 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2025 | Initial Analysis | [email protected] |
| Apr 21, 2025 | New CVE Received | [email protected] |
| Apr 21, 2025 | CVE Modified | CISA-ADP |