Skip to content

Docs: Add a chapter on security - #75

Open
hilman2 wants to merge 1 commit into
CheetahTemplate3:masterfrom
hilman2:docs-security
Open

Docs: Add a chapter on security#75
hilman2 wants to merge 1 commit into
CheetahTemplate3:masterfrom
hilman2:docs-security

Conversation

@hilman2

@hilman2 hilman2 commented Aug 26, 2026

Copy link
Copy Markdown

Addresses #68.

New chapter in the User's Guide: a template is code, where user input belongs instead, and why compiler settings are not a security boundary. The PoC from the issue runs unchanged with useNameMapper=False and with every directive in disabledDirectives, so the chapter says so.

Also a short paragraph in the README, which is where people land first.

No sandbox is proposed. Restricting Python expressions inside the same interpreter has a long history of escapes, so the chapter points at process isolation instead.

Cheetah compiles a template into a Python module and runs it, so a
template built from user input is remote code execution. No compiler
setting prevents it: the example in the chapter runs unchanged with
useNameMapper=False and with every directive disabled.

The chapter says where user input belongs instead, and what to do
when templates really are untrusted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants