HIGHVulnerability

CVE-2026-82447

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-82447
signal_observed_at
2026-09-23T22:44:40+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-29T13:16:38.643
last_modified
2026-09-23T17:17:46.140

Related Entities (2)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements Used in a Template Engine

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82447 — Ninja Signal Threat Intelligence | Ninja Signal