Skip to content
HaystackGHSA-hx9v-6r9f-w677

Insecure Jinja2 templates rendered in Haystack Components can lead to RCE

High7.5CVE-2024-41950 · Published Jul 31, 2024 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
haystack-ai
PyPI
< 2.3.12.3.1
Details and references

### Impact Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions. Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code. ### Patches The problem has been fixed with PRs deepset-ai/haystack#8095 and deepset-ai/haystack#8096. Both have been released with Haystack `2.3.1`. ### Workarounds Prevent users from running the affected Components, or only let users use preselected templates. ### References The list of impacted Components can be found in the release notes for `2.3.1`. https://github.com/deepset-ai/haystack/releases/tag/v2.3.1

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-1336
Also known as
CVE-2024-41950, PYSEC-2026-1447

More Haystack advisories

All Haystack
DateAdvisory
Mar 302023Use of hard-coded, security-relevant constants in deepset-ai/haystack
CVE-2023-1712Critical9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.