Sceawere
Vulnerability Detail
CVE-2026-77177UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Open GenAI Stack SSTI Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 9h ago
- Vendor
- n/a
- Product
- n/a
- Attack Type
- n/a
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-09-29T16:17:11.363Z",
"pubdate": "2026-09-29T16:17:11.363Z",
"executiveSummary": "The Open GenAI Stack (ogx-ai), specifically version 2026-06-11, is susceptible to a critical Server-Side Template Injection (SSTI) vulnerability. This flaw arises from the improper handling of user-supplied input within templates processed by the Jinja2 engine, leading to unauthorized server-side expression evaluation.\nThe vulnerability allows an unauthenticated remote attacker to achieve arbitrary code execution on the underlying host. By injecting malicious Jinja2 syntax into prompts, an attacker can escape the intended application sandbox and execute arbitrary commands with the privileges of the service account.\nGiven its integration into the Meta AI backend for products such as WhatsApp, this vulnerability presents a significant risk to the confidentiality, integrity, and availability of affected systems. Successful exploitation does not require prior authentication, and the impact is limited only by the permissions of the application process. Organizations leveraging this stack must prioritize mitigation efforts to prevent potential system compromise and unauthorized data access.",
"technicalDetails": "The core of the vulnerability lies in the insecure integration of the Jinja2 templating engine within the Open GenAI Stack (ogx-ai) 2026-06-11. The application fails to adequately sanitize or escape user-provided prompt data before passing it to the template rendering pipeline. Consequently, the Jinja2 engine interprets maliciously crafted user input as executable template instructions rather than plain text data.\nExploitation is achieved by leveraging Jinja2 expression syntax, typically enclosed in double curly braces (e.g., {{ ... }}). By crafting a payload that accesses the underlying Python environment's introspection capabilities—such as the __globals__, __subclasses__, or __init__.__globals__ attributes—an attacker can traverse the object hierarchy to gain access to sensitive modules like the 'os' or 'subprocess' libraries.\nThe attack flow proceeds as follows: 1) An attacker identifies an input vector that is processed by the backend Jinja2 template engine; 2) The attacker injects a specially crafted payload, such as '{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}'; 3) The server receives the prompt and renders the template, executing the injected Python code during the evaluation phase; 4) The results of the command execution are returned to the attacker or lead to further malicious activity within the server environment.\nThis vulnerability constitutes a high-severity Remote Code Execution (RCE) primitive. The lack of input sanitization acts as the primary root cause. Because the template engine is permitted to evaluate expressions that access Python's runtime environment, the sandbox is effectively bypassed. The impact is significant, as it enables the execution of arbitrary system commands, potential exfiltration of environment variables containing API keys or credentials, and full compromise of the application instance. The vulnerability is network-exposed, reachable via any interface that accepts user prompts for processing through the stack's templating pipeline."
}