
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34172 is a server-side template injection (SSTI) vulnerability in the giskard-agents Python library that enables remote code execution on any server hosting an application that passes user input to ChatWorkflow.chat(). The vulnerability was published on March 26, 2026, by maintainer mattbit and added to the GitHub Advisory Database on March 27, 2026. Affected versions include giskard-agents ≤ 0.3.3 and 1.0.1a1 through 1.0.2a1; patched versions are 0.3.4 (stable) and 1.0.2b1 (pre-release). It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (Github Advisory, Giskard Advisory).
The root cause is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). In workflow.py (~line 261), ChatWorkflow.chat() converts any raw string argument directly into a MessageTemplate with the string as content_template. This template is then rendered via _inline_env.from_string() in message.py, where _inline_env is a standard Jinja2 Environment with autoescape=False — not a SandboxedEnvironment. Because Jinja2's standard Environment permits access to Python dunder attributes, an attacker can craft a payload using the __class__.__mro__ traversal chain to reach os.popen() and execute arbitrary system commands. Exploitation requires low privileges (an authenticated user who can submit input to the chat interface) and no user interaction beyond the attacker's own actions (Github Advisory, Giskard Advisory).
Successful exploitation grants an authenticated attacker full remote code execution on the server hosting the vulnerable application, with the ability to execute arbitrary system commands, read arbitrary files, and access environment variables (including secrets, API keys, and credentials). The impact spans all three security pillars — confidentiality, integrity, and availability — at a high level. Depending on the server's network position, a compromised host could serve as a pivot point for lateral movement into internal infrastructure (Github Advisory, Giskard Advisory).
A proof-of-concept (PoC) exploit with concrete step-by-step instructions is publicly available in the GitHub Security Advisory, demonstrating the class traversal chain needed to achieve RCE (Giskard Advisory). There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.45% (60th percentile), indicating a moderate relative probability of exploitation within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
giskard-agents ≤ 0.3.3 or 1.0.1a1–1.0.2a1 that expose a chat interface passing user input directly to ChatWorkflow.chat().os.popen. The payload structure is:{{ ''.__class__.__mro__[1].__subclasses__()[INDEX].__init__.__globals__['os'].popen('id').read() }}The INDEX value for the target subclass varies by Python version and must be enumerated (e.g., first probe with {{ ''.__class__.__mro__[1].__subclasses__() | length }} to count available subclasses).ChatWorkflow.chat(user_input)._inline_env.from_string() renders the payload, executing the embedded system command on the server and returning the output (e.g., uid=... from id)./etc/passwd, .env), exfiltrate environment variables, or establish a reverse shell for persistent access (Github Advisory, Giskard Advisory).{{, __class__, __mro__, __subclasses__, __globals__, or os.popen; unexpected Python tracebacks related to Jinja2 template rendering in server logs./bin/sh, bash, curl, wget, python3) executing system commands not part of normal application behavior./tmp, including web shells, scripts, or exfiltration staging files created by the application's service account..env, ~/.aws/credentials) by the application process outside of normal startup behavior (Github Advisory).Upgrade giskard-agents to version 0.3.4 (stable) or 1.0.2b1 (pre-release) immediately. The fix replaces the unsandboxed jinja2.Environment with jinja2.sandbox.SandboxedEnvironment, which blocks access to attributes beginning with _, preventing the __class__.__mro__ traversal chain entirely. As a short-term workaround prior to patching, developers should avoid passing raw user input directly to ChatWorkflow.chat(); instead, use .with_inputs(var=user_data) which passes user data as template variable values (not as template source), and is not affected by this vulnerability (Github Advisory, Giskard Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."