{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/polyaxon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:polyaxon:polyaxon:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-91925"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Polyaxon (\u003c= 2.16.4)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","jinja2","template-injection","polyaxon"],"_cs_type":"advisory","_cs_vendors":["Polyaxon"],"content_html":"\u003cp\u003ePolyaxon versions up to and including 2.16.4 contain a critical vulnerability (CVE-2026-91925) involving the use of an unsandboxed Jinja2 template rendering environment. During server-side run preparation, the application processes several operation specification fields, including queues, namespace, conditions, presets, and dependencies. Because these fields are processed without adequate sandboxing, an authenticated user can inject arbitrary Jinja2 syntax to achieve remote code execution (RCE) in the context of the Polyaxon scheduler process. Successful exploitation allows an attacker to bypass security controls, gain access to underlying infrastructure, and exfiltrate highly sensitive data, including database credentials and internal service tokens used for system authentication. Defenders should prioritize patching and monitor for anomalous process activity originating from the Polyaxon scheduler.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker authenticates to the Polyaxon web interface or API.\u003c/li\u003e\n\u003cli\u003eThe attacker constructs a malicious operation specification payload containing Jinja2 template injection syntax.\u003c/li\u003e\n\u003cli\u003eThe attacker submits a new run or modifies an existing run configuration, populating fields such as 'queues', 'namespace', 'conditions', 'presets', or 'dependencies' with the malicious payload.\u003c/li\u003e\n\u003cli\u003eThe Polyaxon scheduler process receives the run preparation request.\u003c/li\u003e\n\u003cli\u003eThe server-side rendering engine evaluates the Jinja2 template within the attacker-supplied fields.\u003c/li\u003e\n\u003cli\u003eThe underlying OS command is executed by the scheduler process.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the command execution context to query environment variables, read configuration files, or steal service tokens.\u003c/li\u003e\n\u003cli\u003eFinal impact is achieved through exfiltration of sensitive credentials or lateral movement within the environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to full remote code execution on the server hosting the Polyaxon scheduler. Given the access level required for the scheduler, this enables an attacker to retrieve database credentials, service tokens, and potentially interact with the broader Kubernetes or cloud environment where Polyaxon is deployed. This threat affects all users of Polyaxon versions 2.16.4 and earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Polyaxon to a version released after 2.16.4 that includes sandboxed Jinja2 template rendering.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and access control policies for users permitted to define or modify operation specifications.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the Polyaxon API to identify users frequently submitting complex operation specifications containing template-related characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T11:40:13Z","date_published":"2026-09-15T11:40:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-polyaxon-rce/","summary":"Authenticated users can execute arbitrary commands on the Polyaxon scheduler process by injecting malicious Jinja2 payloads into operation specification fields.","title":"Remote Code Execution in Polyaxon via Unsandboxed Jinja2 Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-polyaxon-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Polyaxon","version":"https://jsonfeed.org/version/1.1"}