What happened
NVD published CVE-2026-77177 (CVSS 9.8, Critical) on 2026-09-29 for Open GenAI Stack (ogx-ai), a GenAI stack deployed as the Meta AI backend for WhatsApp. Prompt injection using Jinja2 template syntax bypasses sanitization and achieves server-side expression evaluation, leading to arbitrary code execution. CISA SSVC marks exploitation as 'poc', automatable 'yes', technical impact 'total'.
Why it matters
This is a direct prompt-injection-to-RCE chain in a production LLM backend serving Meta AI on WhatsApp: the exact 'indirect prompt injection becomes code execution' class defenders must treat as hostile, on one of the largest consumer AI surfaces. Any GenAI stack that evaluates user-supplied templates server-side without sanitization is exposed; attackers get full code execution on the model-serving backend.
Attack vector
Remote, unauthenticated. An attacker crafts a prompt containing Jinja2 template syntax that reaches the server-side expression-evaluation path without sanitization, converting prompt injection into code execution.
Affected systems
Open GenAI Stack (ogx-ai), build 2026-06-11 and prior; used as the Meta AI backend for WhatsApp and other products
Mitigation
No released ogx-ai patch referenced in the advisory; template evaluation paths must be audited to remove Jinja2 expression evaluation on user/prompt-controlled input. Monitor gist (first reference) and ogx-ai releases.