SCA: security update for pretix (GHSA-r8p8-qw9w-j9qv)

critical Tenable Self-Hosted Container Security Plugin ID 437857

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when
{name} is used in an email template, it will be replaced with the buyer's name for the final email. This
mechanism contained two security-relevant bugs: * It was possible to exfiltrate information about the
pretix system through specially crafted placeholder names such as {{event.__init__.__code__.co_filename}}.
This way, an attacker with the ability to control email templates (usually every user of the pretix
backend) could retrieve sensitive information from the system configuration, including even database
passwords or API keys. pretix does include mechanisms to prevent the usage of such malicious placeholders,
however due to a mistake in the code, they were not fully effective for the email subject. * Placeholders
in subjects and plain text bodies of emails were wrongfully evaluated twice. Therefore, if the first
evaluation of a placeholder again contains a placeholder, this second placeholder was rendered. This
allows the rendering of placeholders controlled by the ticket buyer, and therefore the exploitation of the
first issue as a ticket buyer. Luckily, the only buyer-controlled placeholder available in pretix by
default (that is not validated in a way that prevents the issue) is {invoice_company}, which is very
unusual (but not impossible) to be contained in an email subject template. In addition to broadening the
attack surface of the first issue, this could theoretically also leak information about an order to one of
the attendees within that order. However, we also consider this scenario very unlikely under typical
conditions. Out of caution, we recommend that you rotate all passwords and API keys contained in your
pretix.cfg https://docs.pretix.eu/self-hosting/config/ file. (CVE-2026-2415)

Solution

Update the pretix library and its related packages to version 2025.10.2 or later.

See Also

https://github.com/advisories/GHSA-r8p8-qw9w-j9qv

Plugin Details

Severity: Critical

ID: 437857

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 2/19/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-2415

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9

Threat Score: 7.5

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/16/2026

Vulnerability Publication Date: 2/16/2026

Reference Information

CVE: CVE-2026-2415

cwe: CWE-627