CVE-2026-77177
Received Received - Intake

Code Execution via Prompt Injection in Open GenAI Stack

Vulnerability report for CVE-2026-77177, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77177 is a Server-Side Template Injection (SSTI) flaw in Open GenAI Stack (ogx-ai) version 2026-06-11. It allows remote code execution by injecting unsanitized Jinja2 template syntax through prompt injection, enabling server-side expression evaluation without proper checks.

Detection Guidance

To detect this SSTI vulnerability, test for Jinja2 template injection by sending payloads like {{7*7}} or {{config.__class__.__init__.__globals__['os'].popen('id').read()}}. If the server returns 49 or executes commands, the system is vulnerable.

Impact Analysis

This vulnerability could allow attackers to execute arbitrary code on the server with root privileges. For users of affected systems like Meta AI backend for WhatsApp, it may lead to data breaches, unauthorized access, or complete system compromise if exploited.

Compliance Impact

This vulnerability likely violates compliance requirements under GDPR and HIPAA due to unauthorized data access or exposure risks. Organizations using affected systems may face regulatory penalties, legal liabilities, and reputational damage from potential data breaches.

Mitigation Strategies

Immediately update the Open GenAI Stack to the latest patched version. Disable prompt injection features if possible. Implement strict input sanitization for Jinja2 templates. Restrict server-side command execution permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77177. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart