HighVulnerabilityLLM-specific
CVE-2026-77177: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-77177
- Published
- Record updated
Summary
CVE-2026-77177 affects Open GenAI Stack (aka ogx-ai) dated 2026-06-11, as used in the Meta AI backend for WhatsApp and other products. Prompt injection that carries Jinja2 template syntax can trigger server-side expression evaluation without sanitization, allowing code execution.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- InfoCan you trust Meta’s Muse or OpenAI’s Dots to run your life?Same vendor · The Verge (AI)
- InfoAI startup Manus raises $500 million in first funding round since Meta breakupSame vendor · CNBC Technology
- InfoMicrosoft to sell $2,599 Surface Laptop Ultra containing Nvidia AI chipSame vendor · CNBC Technology
- InfoIt appears .agent and .agi are about to be the hot new domainsSame vendor · The Verge (AI)
- InfoMuse launches on the iPadSame vendor · The Verge (AI)