CVE-2026-44209: Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass u...

Added to the CISA Known Exploited Vulnerabilities catalog on 26 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Inj...

Required action: Review and patch if applicable to your AI infrastructure.