Rating:

Flask Server-Side Template Injection (SSTI)

Original writeup (https://ctf.zeyu2001.com/2021/csaw-ctf-qualification-round-2021/ninja).