LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-82447

Published
CVSS8.8
Severityhigh
WeaknessCWE-1336
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-82447

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-82447.