haystack-ai is vulnerable to Template Injection
71
High Risk
ChatPromptBuilder renders Jinja2 string templates using a custom Chat extension. Values substituted for template variables could be interpreted as structured chat content (for example multimodal or tool-related payloads) rather than literal user text. During rendering, the extension now normalizes those substitution results so variable output is treated as plain text, with tests covering delimiter and payload cases that previously crossed that boundary.
You are affected if you are using a version that falls within the vulnerable range.
haystack-ai is vulnerable to Template Injection in versions 2.16.0 - 2.26.0.
Upgrade the haystack-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant