PT-2026-21491 · Datapizza · Datapizza-Ai

Edoardottt

·

Publicado

2026-02-22

·

Atualizado

2026-02-23

·

CVE-2026-2969

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions datapizza-labs datapizza-ai version 0.0.2
Description A flaw exists in the Jinja2 Template Handler component of datapizza-ai. Specifically, the ChatPromptTemplate function within the datapizza-ai-core/datapizza/modules/prompt/prompt.py file is susceptible to improper neutralization of special elements used in a template engine due to manipulation of the Prompt argument. This allows for remote exploitation. The exploit has been published. The vendor was contacted but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2969
GHSA-Q5XX-FXV3-XXQF

Produtos afetados

Datapizza-Ai