High severity8.8NVD Advisory· Published Aug 29, 2026
CVE-2026-82447
CVE-2026-82447
Description
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.0.45
Patches
Vulnerability mechanics
References
4- github.com/Skyvern-AI/skyvern/blob/v1.0.44/skyvern/forge/sdk/prompting.pynvd
- github.com/Skyvern-AI/skyvern/blob/v1.0.44/skyvern/forge/sdk/workflow/models/block.pynvd
- github.com/Skyvern-AI/skyvern/commit/d723de621d5b3a340f3cc4d5b46bfe40a9a3124envd
- www.vulncheck.com/advisories/skyvern-before-1.0.45-sandbox-escape-via-textpromptblocknvd
News mentions
0No linked articles in our index yet.