CVE-2026-34172: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34172 is a server-side template injection (SSTI) vulnerability in the giskard-agents Python library that enables remote code execution on any server hosting an application that passes user input to ChatWorkflow.chat(). The vulnerability was published on March 26, 2026, by maintainer mattbit and added to the GitHub Advisory Database on March 27, 2026. Affected versions include giskard-agents ≤ 0.3.3 and 1.0.1a1 through 1.0.2a1; patched versions are 0.3.4 (stable) and 1.0.2b1 (pre-release). It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (Github Advisory, Giskard Advisory).

Technical details

The root cause is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). In workflow.py (~line 261), ChatWorkflow.chat() converts any raw string argument directly into a MessageTemplate with the string as content_template. This template is then rendered via _inline_env.from_string() in message.py, where _inline_env is a standard Jinja2 Environment with autoescape=False — not a SandboxedEnvironment. Because Jinja2's standard Environment permits access to Python dunder attributes, an attacker can craft a payload using the __class__.__mro__ traversal chain to reach os.popen() and execute arbitrary system commands. Exploitation requires low privileges (an authenticated user who can submit input to the chat interface) and no user interaction beyond the attacker's own actions (Github Advisory, Giskard Advisory).

Impact

Successful exploitation grants an authenticated attacker full remote code execution on the server hosting the vulnerable application, with the ability to execute arbitrary system commands, read arbitrary files, and access environment variables (including secrets, API keys, and credentials). The impact spans all three security pillars — confidentiality, integrity, and availability — at a high level. Depending on the server's network position, a compromised host could serve as a pivot point for lateral movement into internal infrastructure (Github Advisory, Giskard Advisory).

Exploitability

A proof-of-concept (PoC) exploit with concrete step-by-step instructions is publicly available in the GitHub Security Advisory, demonstrating the class traversal chain needed to achieve RCE (Giskard Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.45% (60th percentile), indicating a moderate relative probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).

Exploitation steps

  1. Identify a vulnerable target: Locate applications built with giskard-agents ≤ 0.3.3 or 1.0.1a1–1.0.2a1 that expose a chat interface passing user input directly to ChatWorkflow.chat().
  2. Obtain low-privilege access: Authenticate to the application with any valid user account, as the vulnerability requires only low privileges.
  3. Craft a Jinja2 SSTI payload: Construct a payload using Python's class traversal chain to reach os.popen. The payload structure is:
    {{ ''.__class__.__mro__[1].__subclasses__()[INDEX].__init__.__globals__['os'].popen('id').read() }}
    The INDEX value for the target subclass varies by Python version and must be enumerated (e.g., first probe with {{ ''.__class__.__mro__[1].__subclasses__() | length }} to count available subclasses).
  4. Submit the payload via the chat interface: Pass the crafted Jinja2 template string as the message to the application's chat endpoint, which internally calls ChatWorkflow.chat(user_input).
  5. Achieve RCE: The non-sandboxed _inline_env.from_string() renders the payload, executing the embedded system command on the server and returning the output (e.g., uid=... from id).
  6. Escalate: Use the RCE primitive to read sensitive files (/etc/passwd, .env), exfiltrate environment variables, or establish a reverse shell for persistent access (Github Advisory, Giskard Advisory).

Indicators of compromise

  • Logs: Application logs showing chat messages containing Jinja2 template syntax such as {{, __class__, __mro__, __subclasses__, __globals__, or os.popen; unexpected Python tracebacks related to Jinja2 template rendering in server logs.
  • Process: Unusual child processes spawned by the Python application process (e.g., /bin/sh, bash, curl, wget, python3) executing system commands not part of normal application behavior.
  • Network: Unexpected outbound connections from the application server to external IPs, particularly on non-standard ports, following chat interactions; DNS lookups for attacker-controlled domains initiated by the application process.
  • File System: New or modified files in the application directory or /tmp, including web shells, scripts, or exfiltration staging files created by the application's service account.
  • Environment: Evidence of environment variable access or credential files being read (e.g., .env, ~/.aws/credentials) by the application process outside of normal startup behavior (Github Advisory).

Mitigation and workarounds

Upgrade giskard-agents to version 0.3.4 (stable) or 1.0.2b1 (pre-release) immediately. The fix replaces the unsandboxed jinja2.Environment with jinja2.sandbox.SandboxedEnvironment, which blocks access to attributes beginning with _, preventing the __class__.__mro__ traversal chain entirely. As a short-term workaround prior to patching, developers should avoid passing raw user input directly to ChatWorkflow.chat(); instead, use .with_inputs(var=user_data) which passes user data as template variable values (not as template source), and is not affected by this vulnerability (Github Advisory, Giskard Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management