MEDIUM6.5
PYSEC-2026-1804
Azure PromptFlow remote code execution related to Jinja templates
Quick fix
PYSEC-2026-1804 — promptflow-core: upgrade to the fixed version with the command below.
pip install --upgrade 'promptflow-core>=1.17.2'Details
Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/promptflow-core
Introduced in:
0Fixed in: 1.17.2Fix
pip install --upgrade 'promptflow-core>=1.17.2'References
- https://nvd.nist.gov/vuln/detail/CVE-2025-24986[ADVISORY]
- https://github.com/microsoft/promptflow/commit/5f4a41ab4cb15607ade7f26138b0b863b4e4eb0a[WEB]
- https://github.com/microsoft/promptflow/commit/625061724c51533d28fe6e0e3014b1042afdb07f[WEB]
- https://github.com/microsoft/promptflow[PACKAGE]
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24986[WEB]
- https://pypi.org/project/promptflow-core[PACKAGE]
- https://github.com/advisories/GHSA-gprr-v9f2-px3c[ADVISORY]