Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gphh-9q3h-jgpp | banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI |
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Masci
Masci banks |
|
| Vendors & Products |
Masci
Masci banks |
Tue, 26 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system. This vulnerability is fixed in 2.4.2. | |
| Title | Banks: Critical Remote Code Execution (RCE) via Jinja2 SSTI | |
| Weaknesses | CWE-1336 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-28T14:07:44.481Z
Reserved: 2026-05-05T15:13:47.571Z
Link: CVE-2026-44209
No data.
Status : Deferred
Published: 2026-05-26T21:16:37.620
Modified: 2026-06-17T10:50:21.683
Link: CVE-2026-44209
No data.
OpenCVE Enrichment
Updated: 2026-05-27T10:08:28Z
Github GHSA