In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
{ "urgency": "not yet assigned" }