1.4.2
1.4.2
Released: Tue Sep 22 2026
bug
-
[bug] [tests] Adjusted the test suite to accommodate for a change in Pygments 2.21.0
where theHtmlFormatternow renders"and'characters
literally rather than as HTML entities, which caused failures in tests
that assert against the rendered output of
html_error_template().References: #440
-
[bug] [template] Fixed issue in
TemplateLookupwhere a URI beginning with a drive
designator (e.g.C:/../../secret.txt) could bypass the directory
traversal check on Windows, allowing reads of arbitrary files outside of
the template directory. The check inTemplatenormalized the URI
usingos.path, which on Windows isntpath; asntpathsplits the
drive designator off and treats the remainder as rooted, the..
segments were absorbed before the check could inspect them. Normalization
is now performed withposixpath, which is the same module used by
TemplateLookup.get_template()to resolve the URI to a file.References: #441