Giskard is an ML testing and validation platform with a focused product footprint centered on its core framework and agent components, presenting an attack surface oriented toward template-processing and input-parsing mechanisms. Observed vulnerabilities cluster around template injection and irregular-expression complexity, reflecting the nature of dynamic code generation and pattern-matching inherent to machine-learning test automation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Giskard over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-34172HIGH Giskard is an open-source Python library for testing and evaluating agentic systems. Prior to versions 0.3.4 and 1.0.2b1, ChatWorkflow.chat(message) passes its string argument dire | Mar 31, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-40320HIGH Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() c | Apr 17, 2026 | 7.8 | 25 | NO | NO |
CVE-2026-40319MEDIUM Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes a user-supplied regular expression pattern directly to Pytho | Apr 17, 2026 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Giskard.
Media articles that mention a CVE ID that affects a product developed by Giskard — matched by CVE ID, not by vendor name.