CVE-2026-2969 is a high-severity vulnerability affecting datapizza-labs datapizza-ai 0.0.2, specifically within the Jinja2 Template Handler's ChatPromptTemplate function. This flaw allows for remote exploitation due to improper neutralization of special elements in template engine arguments. With a CVSS score of 7.2, the vulnerability presents a high risk of compromise to confidentiality, integrity, and availability. An exploit has been published, indicating readily available attack methods, yet there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.0.2CPE matchmatch criteria | cpe:2.3:a:datapizza:datapizza_ai:0.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.