Seems like someone filed CVE-2026-0685.
Impact
If an attacker can influence or inject template expressions, this vulnerability allows arbitrary code execution with the privileges of the running application.
I think this "CVE" is completely pointless. Genshi allows running actual Python code via <?python in its templates so when you are able to control the template, it's game over anyway.
I'll close the automatically created Fedora bugs as "not a bug" but another pair of eyes would be helpful ( ping @hodgestar)
Seems like someone filed CVE-2026-0685.
I think this "CVE" is completely pointless. Genshi allows running actual Python code via
<?pythonin its templates so when you are able to control the template, it's game over anyway.I'll close the automatically created Fedora bugs as "not a bug" but another pair of eyes would be helpful ( ping @hodgestar)