giskard-agents
A lightweight library that orchestrates LLM completions and agents in parallel workflows
Activity
- Latest release
- 2w ago
- Total releases
- 15
- Cadence
- ~20 days
- Last 12 months
- 15
Details
- License
- MIT
- First release
- Nov 04, 2025
| Version | Released | |
|---|---|---|
1.0.2
major
|
1.0.2
major
Dependencies (10)
+ 2 more |
|
1.0.2rc1
pre
|
1.0.2rc1
pre
Dependencies (10)
+ 2 more |
|
1.0.2b6
pre
|
1.0.2b6
pre
Dependencies (10)
+ 2 more |
|
1.0.2b5
pre
|
1.0.2b5
pre
Dependencies (10)
+ 2 more |
|
1.0.2b4
pre
|
1.0.2b4
pre
Dependencies (10)
+ 2 more |
|
1.0.2b3
pre
|
1.0.2b3
pre
Dependencies (10)
+ 2 more |
|
1.0.2b2
pre
|
1.0.2b2
pre
Dependencies (10)
+ 2 more |
|
1.0.2b1
pre
|
1.0.2b1
pre
Dependencies (9)
+ 1 more |
|
0.3.4
patch
|
0.3.4
patch
Dependencies (8)
|
|
1.0.2a1
pre
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.2a1
pre
Dependencies (9)
+ 1 more |
|
1.0.1a1
pre
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
1.0.1a1
pre
Dependencies (9)
+ 1 more |
|
0.3.3
patch
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
0.3.3
patch
Dependencies (8)
|
|
0.3.2
patch
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
0.3.2
patch
Dependencies (8)
|
|
0.3.1
patch
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
0.3.1
patch
Dependencies (8)
|
|
0.3.0
initial
1 CVE
CVE-2026-34172
PYSEC-2026-2487
GHSA-frv4-x25r-588m
Jul 13, 2026
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
Critical
Network
Low
Low
None
Summary
The method name Root Cause
The string becomes
The Jinja2 Environment is not sandboxed:
Proof of Concept
A developer building a chatbot:
Note: using ImpactRemote code execution on the server hosting any application built with giskard-agents that passes user input to Affects giskard-agents <=0.3.3 and 1.0.x alpha. Patched in giskard-agents 0.3.4 (stable) and 1.0.2b1 (pre-release). MitigationUpdate to 0.3.4 (or 1.0.2b1 for the pre-release branch) which includes the fix. The fix replaces the unsandboxed Jinja2 Environment with Affected versions
0.3.0
0.3.1
0.3.2
0.3.3
1.0.1a1
1.0.2a1
Fixed in
0.3.4
1.0.2b1
References Updated Jul 13, 2026 · Source: OSV.dev |
0.3.0
initial
Dependencies (7)
|