CVE-2025-24986Medium· 6.5▾ SunlitAzure PromptFlow remote code execution related to Jinja templates
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.5%
0.5% → 0.5%
Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.
promptflow-tools < 1.6.0promptflow-core < 1.17.2Upgrade to a patched release:
promptflow-tools 1.6.0promptflow-core 1.17.2