CVE-2026-33154 | dynaconf up to 3.2.12 on Python Configuration special elements used in a template engine (GHSA-pxrr-hq57-q35p / Nessus ID 303261)
A vulnerability described as problematic has been identified in dynaconf up to 3.2.12 on Python. This affects an unknown part of the component Configuration Handler. Such manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is uniquely identified as CVE-2026-33154. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.