CRITICAL
wizarrrr
CVE published 2026-10-09
CVE-2026-108264
Authenticated Server-Side Template Injection (SSTI) in Wizarr's wizard step rendering leads to Remote Code Execution (RCE). The vulnerability allows an authenticated user to execute arbitrary Python code, which could lead to a compromise of the system and sensitive information disclosure. This issue is critical, with a CVSS score of 9.1, and requires immediate attention from administrators and users of Wi [truncated]