In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
CVE-2019-10906 (Candidate) is related to these bugs: