CVE-2026-108264: Wizarr: Authenticated Server-Side Template Injection (SSTI) in wizard step rendering leads to Remote Code Execution (RCE)
Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinjafilters.py and app/services/wizardwidgets.py contained additional evaluation sinks. This could execute operating-system commands as the application user, disclose the Flask SECRETKEY, access connected service credentials and the database, and produce stored cross-site scripting. This issue is fixed in 2026.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Wizarrto a version that resolves this vulnerability.Fixed in 2026.9.1
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated user who can create wizard steps can supply malicious Markdown. An administrator can also introduce the payload by importing an untrusted wizard bundle through POST /settings/wizard/import.
When does the malicious payload execute?
The stored payload is evaluated when GET /wizard/{server}/{idx} renders the affected wizard step. The issue also has additional evaluation sinks in app/jinja_filters.py and app/services/wizard_widgets.py.
What access could successful exploitation provide?
Code executes as the application user and may allow operating-system command execution. It can also expose the Flask SECRET_KEY, connected service credentials, and database data, and can create stored cross-site scripting.
What should teams do if they cannot upgrade immediately?
Do not allow untrusted users to create wizard steps, and do not import untrusted wizard bundles. Review existing stored wizard-step Markdown and imported bundles for potentially malicious content, since rendering a stored step triggers evaluation.
How can I determine whether my deployment is affected?
Wizarr versions prior to 2026.9.1 are affected. Check whether users can create wizard steps or whether administrators have imported bundles, then inspect stored step content because it is evaluated on wizard rendering.