{"id":"CVE-2026-77177","published":"2026-09-29T16:17:11.363","lastModified":"2026-09-29T20:17:26.403","description":"Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","tags":[]},{"url":"https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","tags":[]}],"exploitRefs":[{"url":"https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","tags":[]},{"url":"https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows code execution via prompt injection with Jinja2 template syntax, leading to server-side expression evaluation without proper sanitization.","exploitability":"Exploitation is relatively straightforward given the lack of sanitization, requiring an attacker to craft a malicious prompt.","blast_radius":"If exploited, this could lead to full server compromise, potentially affecting Meta AI backend services for WhatsApp and other products.","remediation":"Disable the affected feature or upgrade to the latest version of Open GenAI Stack (ogx-ai) as soon as possible.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","jinja2","server-side","code-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T08:46:53.510Z"}}