OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-77177

CRITICAL · CVSS 9.8 EPSS 0.59% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Open GenAI Stack, utilized in the Meta AI backend for WhatsApp and other applications, is vulnerable to prompt injection attacks that exploit Jinja2 template syntax, enabling unauthorized code execution through server-side expression evaluation without proper sanitization. This vulnerability poses a significant risk to any systems relying on this stack, particularly those handling sensitive data or user interactions. Organizations using the affected products should prioritize remediation efforts to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77177
Severity
CRITICAL
CVSS
9.8
EPSS
0.59%

Original NVD Description

Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluation without sanitization.