In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-41949.json"