CVE-2025-23211: Tandoor Recipes - SSTI - Remote Code Execution

10.0 CVSS

Description

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. This vulnerability is fixed in 1.5.24.

Classification

CVE ID: CVE-2025-23211

CVSS Base Severity: CRITICAL

CVSS Base Score: 10.0

Affected Products

Vendor: TandoorRecipes

Product: recipes

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.25% (scored less or equal to compared to others)

EPSS Date: 2025-02-27 (when was this score calculated)

References

https://github.com/TandoorRecipes/recipes/security/advisories/GHSA-r6rj-h75w-vj8v
https://github.com/TandoorRecipes/recipes/commit/e6087d5129cc9d0c24278948872377e66c2a2c20
https://github.com/TandoorRecipes/recipes/blob/4f9bff20c858180d0f7376de443a9fe4c123a50c/cookbook/helper/template_helper.py#L95

Timeline