{"id":"CVE-2026-77177","title":"Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluati…","summary":"Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluati…","severity":"none","published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:11.363","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77177","references":[{"url":"https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.268Z","slug":"CVE-2026-77177","body":"## Overview\n\nOpen GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}