Vulnerability Description
Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input allows authenticated users to inject crafted expressions that are evaluated on the server, leading to blind remote code execution (RCE).
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://cristibtz.github.io/posts/CVE-2025-49619/
- https://github.com/Skyvern-AI/skyvern/commit/db856cd8433a204c8b45979c70a4da1e119
- https://www.exploit-db.com/exploits/52335
- https://cristibtz.blog/posts/CVE-2025-49619/
FAQ
What is CVE-2025-49619?
CVE-2025-49619 is a vulnerability with a CVSS score of 8.5 (HIGH). Skyvern through 0.1.85 is vulnerable to server-side template injection (SSTI) in the Prompt field of workflow blocks such as the Navigation v2 Block. Improper sanitization of Jinja2 template input all...
How severe is CVE-2025-49619?
CVE-2025-49619 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-49619?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.