Skip to content
Threat Feed

Tag

Jinja2

4 briefs RSS
high advisory

Remote Code Execution in Polyaxon via Unsandboxed Jinja2 Injection

Authenticated users can execute arbitrary commands on the Polyaxon scheduler process by injecting malicious Jinja2 payloads into operation specification fields.

Polyaxon remote-code-execution jinja2 template-injection
1t 1c
high advisory

Trestle Server-Side Template Injection via Custom Jinja2 Extensions

The Trestle command-line tool is vulnerable to Server-Side Template Injection (SSTI) due to the unsafe re-evaluation of untrusted Markdown content as Jinja2 template code.

trestle ssti rce python jinja2
1t
critical advisory

Giskard-agents ChatWorkflow.chat() Server-Side Template Injection

Giskard-agents versions 0.3.3 and earlier, and versions 1.0.1a1 through 1.0.2a1 are vulnerable to remote code execution via server-side template injection where the ChatWorkflow.chat() method passes user-supplied strings directly to a non-sandboxed Jinja2 Environment, allowing attackers to execute arbitrary code on the server.

ssti jinja2 rce giskard-agents vulnerability
2r 1t
high advisory

banks Library Vulnerable to Server-Side Template Injection Leading to Remote Code Execution

banks version 2.4.1 and earlier is vulnerable to Server-Side Template Injection (SSTI) due to the use of an unsandboxed Jinja2 environment, allowing attackers to achieve Remote Code Execution (RCE) by injecting malicious code through user-supplied prompt templates.

banks ssti rce jinja2
2r 2t 2c