CRITICAL 9.8 NVD
CVE-2026-77177
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with J
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.
References
- https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb
- https://gist.github.com/abhi04anon/8ce0b68a5a7dda8a0501cbaf933173eb
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-29 via NVD.
Risk Timeline
CVE Disclosed2026-09-29 · 0 days ago
Remediation Resources
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.