{"data":{"id":"c8223350-3597-4e56-883d-bdd9de657179","title":"CVE-2026-77177: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code…","summary":"CVE-2026-77177 affects Open GenAI Stack (aka ogx-ai) dated 2026-06-11, as used in the Meta AI backend for WhatsApp and other products. Prompt injection that carries Jinja2 template syntax can trigger server-side expression evaluation without sanitization, allowing code execution.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77177","publishedAt":"2026-09-29T16:17:11.363Z","cveId":"CVE-2026-77177","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":["Meta"],"affectedVendorsRaw":["Open GenAI Stack (ogx-ai)","Meta AI backend for WhatsApp"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00592,"epssCheckedAt":"2026-10-10T02:57:07.563Z","kevDateAdded":null,"advisoryAliases":["GHSA-9rwh-q28c-cv6g"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:08.172Z","patchAvailable":null,"disclosureDate":"2026-09-29T16:17:11.363Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0051"]}}