PT-2026-22105 · Agenta · Agenta

Mmabrouk

·

Published

2026-02-26

·

Updated

2026-03-19

·

CVE-2026-27961

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Agenta versions prior to 0.86.8
Description Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) issue exists in the API server evaluator template rendering for versions prior to 0.86.8. The vulnerable code is within the SDK package but is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage; it only impacts self-hosted or managed Agenta platform deployments. Server-Side Template Injection (SSTI) allows an attacker to inject malicious code into templates, potentially leading to remote code execution.
Recommendations Upgrade to version 0.86.8 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27961
GHSA-CFR2-MP74-3763
PYSEC-2026-7

Affected Products

Agenta