CVE-2025-49619 EXPLOIT
8.5
HIGH · CVSS 3.1 · EPSS 20% (pctl 97)
Patch early
A public exploit exists.
Description
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).
Scoring
| CVSS | 8.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
| EPSS | 19.97% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-1336 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2025-06-07 |
| Last modified | 2026-06-17 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Skyvern 0.1.85 - Remote Code Execution (RCE) via SSTI | 2025-06-15 |
References
→ the Explorer · watch your stack · NVD