CVE-2026-91925
nicheAuthenticated Jinja2 Template Injection RCE in Polyaxon (through 2.16.4)
Polyaxon through version 2.16.4 renders operation specification fields — including queue, namespace, conditions, presets, and dependencies — using an unsandboxed Jinja2 template environment during server-side run preparation. An authenticated user can submit a run containing Jinja2 template-injection payloads in these fields, which are evaluated by the server and result in arbitrary operating-system command execution in the scheduler process context. Successful exploitation exposes database credentials and service tokens accessible to that process, effectively compromising the Polyaxon control plane and potentially the underlying cluster. Any self-hosted Polyaxon deployment up to and including 2.16.4 that allows run submission by untrusted or semi-trusted users (for example, multi-tenant ML teams) is affected. No public proof of concept is known and there is no evidence of in-the-wild exploitation, though the issue is rated high (CVSS 4.0: 8.7).
What to do: Upgrade Polyaxon to a release newer than 2.16.4 as soon as a fixed version is available and monitor the vendor's advisories. In the interim, restrict access to the Polyaxon API and run-submission endpoints to trusted users only, enforce strict RBAC/tenant separation, and review submitted run specifications for Jinja2 template syntax. If untrusted users could submit runs on an affected instance, rotate database credentials and service tokens and audit scheduler logs for unexpected command execution.
| Polyaxon | All versions through 2.16.4 (<= 2.16.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 payloads in queue, namespace, conditions, presets, or dependencies fields to execute operating system commands in the scheduler process context, exposing database credentials and service tokens.
- Weakness
- CWE-1336
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.