CVE-2026-77177
Last modified
CVE-2026-77177 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization..
Description
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-77177?
How severe is CVE-2026-77177?
How do I fix CVE-2026-77177?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-77165File owners were unable to unlock TYPE_TOKEN locks placed by…6.5
- CVE-2026-77166The emoji field in the page emoji update endpoint does not p…2.4
- CVE-2026-77169A vulnerability in the team folders (formerly group folders)…6.5
- CVE-2026-7717A vulnerability was determined in Totolink WA300 5.2cu.7112_…8.8
- CVE-2026-77170The Deck config API allows authenticated users to set board-…4.3
- CVE-2026-77176A flaw was found in Kata Containers. In configurations utili…8.1
- CVE-2026-77179On macOS, the virtio-fs host server used by Docker Sandboxes…9.4
- CVE-2026-7718A vulnerability was identified in Totolink WA300 5.2cu.7112_…6.3
- CVE-2026-77180When NGINX Ingress Controller is configured with Ingress ann…8.3
- CVE-2026-77181Incorrect Authorization vulnerability in Apache Syncope. …9.8
- CVE-2026-77184In MongoDB Connector for BI, the description text of a colle…5.2
- CVE-2026-77185Authentication bypass in sshd-core in Apache MINA SSHD versi…9.1
Are you affected by CVE-2026-77177?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
