---
id: CVE-2026-77177
title: >-
  Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for
  WhatsApp and other products, allows code execution because prompt injection
  (with Jinja2 template syntax) can be used to achieve server-side expression
  evaluati…
summary: >-
  Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for
  WhatsApp and other products, allows code execution because prompt injection
  (with Jinja2 template syntax) can be used to achieve server-side expression
  evaluati…
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:11.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77177'
references:
  - url: 'https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T16:39:33.268Z'
---

## Overview

Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
