{"id":"PYSEC-2026-1929","summary":"Skyvern has a Jinja runtime leak","details":"Skyvern through 0.2.0 has a Jinja runtime leak in sdk/workflow/models/block.py.","aliases":["CVE-2025-49619","GHSA-h92g-3xc3-ww2r"],"modified":"2026-07-07T17:47:54.202779732Z","published":"2026-07-07T16:02:53.926530Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49619"},{"type":"WEB","url":"https://github.com/Skyvern-AI/skyvern/commit/db856cd8433a204c8b45979c70a4da1e119d949d"},{"type":"WEB","url":"https://cristibtz.blog/posts/CVE-2025-49619"},{"type":"WEB","url":"https://cristibtz.github.io/posts/CVE-2025-49619"},{"type":"PACKAGE","url":"https://github.com/Skyvern-AI/skyvern"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/52335"},{"type":"PACKAGE","url":"https://pypi.org/project/skyvern"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h92g-3xc3-ww2r"}],"affected":[{"package":{"name":"skyvern","ecosystem":"PyPI","purl":"pkg:pypi/skyvern"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.2.0"}]}],"versions":["0.1.53","0.1.55","0.1.56","0.1.62","0.1.63","0.1.64","0.1.66","0.1.67","0.1.68","0.1.69","0.1.70","0.1.71","0.1.72","0.1.73","0.1.74","0.1.75","0.1.76","0.1.77","0.1.78","0.1.79","0.1.81","0.1.82","0.1.83","0.1.84","0.1.85","0.1.86","0.1.88","0.1.89","0.2.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/skyvern/PYSEC-2026-1929.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}