Junglewise Threat Intelligence

CVE-2026-34172: Giskard giskard-agents remote code execution in ChatWorkflow.chat

CVE-2026-34172 · Severity: high · CVSS 8.8 · Published 2026-03-31

Executive brief

Giskard is an open-source Python library used to test and evaluate AI agents. A security flaw allows attackers to execute malicious code on the server hosting the AI application if user-provided text is passed directly to the chat function. This could lead to a total system takeover, unauthorized data access, or service disruption.

Technical details

A Server-Side Template Injection (SSTI) vulnerability exists in the ChatWorkflow.chat() method of the giskard-agents library. The 'message' parameter is passed directly as a Jinja2 template source to a non-sandboxed Environment using from_string(). Because the environment is not sandboxed, an attacker can use Jinja2 class traversal (e.g., accessing __class__.__mro__) to reach the 'os' module and execute arbitrary system commands. The vulnerability is triggered when a developer passes unsanitized user input directly to the chat() method. The issue is fixed in versions 0.3.4 and 1.0.2b1 by migrating to Jinja2's SandboxedEnvironment.

Affected products

  • Giskard-AI giskard-agents <= 0.3.3, >= 1.0.1a1, <= 1.0.2a1

Timeline

  • 2026-03-26: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE published to NVD
  • 2026-03-31: patched: Fix released in versions 0.3.4 and 1.0.2b1

References