peter bassill · operator
$ cve CVE-2025-49619 JSON

CVE-2025-49619 EXPLOIT

8.5
HIGH · CVSS 3.1 · EPSS 20% (pctl 97)

Patch early

A public exploit exists.

Description

Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).

Scoring

CVSS8.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
EPSS19.97% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-1336
On CISA KEVno
Public exploityes
Published2025-06-07
Last modified2026-06-17

Public exploits

SourceTitleDate
exploit-dbSkyvern 0.1.85 - Remote Code Execution (RCE) via SSTI2025-06-15

References

→ the Explorer  ·  watch your stack  ·  NVD