CVE Explorer
CVE-2026-34172
Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its string argument directly as a Jinja2 template source to a non-sandboxed Environment. A developer who passes user input to this method enables full remote code execution via Jinja2 class traversal. The method name chat and parameter name message naturally invite passing user input directly, but the string is silently parsed as a Jinja2 tem
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"giskard-oss","vendor":"Giskard-AI","versions":[{"status":"affected","version":"< 0.3.4"},{"status":"affected","version":">= 1.0.1a1, < 1.0.2b1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e50c5e06a58664f2a0ab943d37edfebd7e724e0d3616c376f87f0c8857800e64 · sha256:2717113d048ec9e3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.7,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e50c5e06a58664f2a0ab943d37edfebd7e724e0d3616c376f87f0c8857800e64 · sha256:2717113d048ec9e3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e50c5e06a58664f2a0ab943d37edfebd7e724e0d3616c376f87f0c8857800e64 · sha256:2717113d048ec9e3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/Giskard-AI/giskard-oss/security/advisories/GHSA-frv4-x25r-588m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e50c5e06a58664f2a0ab943d37edfebd7e724e0d3616c376f87f0c8857800e64 · sha256:2717113d048ec9e3… · /containers/adp/0/references/0
{"name":"https://github.com/Giskard-AI/giskard-oss/security/advisories/GHSA-frv4-x25r-588m","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Giskard-AI/giskard-oss/security/advisories/GHSA-frv4-x25r-588m"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e50c5e06a58664f2a0ab943d37edfebd7e724e0d3616c376f87f0c8857800e64 · sha256:2717113d048ec9e3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.