CVE-2026-2969Disclosure(datapizza / datapizza_ai)

LOWCVSS 7.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in datapizza-labs datapizza-ai 0.0.2. Affected is the function ChatPromptTemplate of the file datapizza-ai-core/datapizza/modules/prompt/prompt.py of the component Jinja2 Template Handler. This manipulation of the argument Prompt causes improper neutralization of special elements used in a template engine. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-791CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • datapizza_ai

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
datapizza_ai

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-22: 202-22
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2969 This repository contains public information for the disclosure of two vulnerabilities in datapizza-ai framework: CVE-2026-2969 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2969

    Post summary

    The repository hosts public disclosure information for CVE-2026-2969 in the datapizza-ai framework, linking to a vulnerability details page.

    0000067
    4.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2970 This repository contains public information for the disclosure of two vulnerabilities in datapizza-ai framework: CVE-2026-2969 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2970

    Post summary

    Repository provides disclosure information for two CVEs in datapizza-ai, with a link to vulmon for CVE-2026-2970.

    0000061
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdatapizzadatapizza_ai0.0.2--

Explore more