VDB
Sign up
MEDIUM4.7

PYSEC-2026-2439

datapizza-ai: Server-Side Template Injection in ChatPromptTemplate via Jinja2 Template Handler

Details

A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt causes improper neutralization of special elements used in a template engine. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/datapizza-ai-core
Introduced in: 0

No fixed version published yet for datapizza-ai-core (pip). Pin to a known-safe version or switch to an alternative.

References