PT-2026-21491 · Datapizza · Datapizza-Ai
Edoardottt
·
Published
2026-02-22
·
Updated
2026-02-23
·
CVE-2026-2969
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
datapizza-labs datapizza-ai version 0.0.2
Description
A flaw exists in the Jinja2 Template Handler component of datapizza-ai. Specifically, the
ChatPromptTemplate function within the datapizza-ai-core/datapizza/modules/prompt/prompt.py file is susceptible to improper neutralization of special elements used in a template engine due to manipulation of the Prompt argument. This allows for remote exploitation. The exploit has been published. The vendor was contacted but did not respond.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Datapizza-Ai