Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Skyvern versions before 1.0.45 contain a critical sandbox escape vulnerability in the TextPromptBlock component that processes workflow prompts through dual rendering stages. The vulnerability stems from rendering user-controlled prompts first in a sandboxed Jinja environment, then again through an unsandboxed environment—a dangerous pattern that defeats the sandbox's protections. Attackers can inject malicious Jinja template syntax via workflow parameters or output from upstream blocks to achieve arbitrary code execution with full server process privileges. This affects any organization deploying Skyvern for automation workflows, particularly those processing untrusted or user-supplied prompt data, making it a critical risk for supply chain attacks and lateral movement within affected infrastructure.
While this CVE currently maps to zero Casky skills due to its specificity to Skyvern's architecture, practitioners using Casky's Claude-powered analysis would detect the underlying attack patterns by examining template injection techniques and sandbox bypass methods. Extended reasoning across Casky's 754 MITRE ATT&CK-mapped skills would surface relevant detection guidance around Code Execution (T1059), Process Injection (T1055), and Exploitation for Privilege Escalation (T1548), particularly when analyzing logs showing template syntax passed through workflow parameters followed by unexpected process execution. Security teams would observe suspicious patterns: Jinja syntax in user inputs, process spawning after prompt processing, and privilege escalation attempts tied to TextPromptBlock operations—enabling them to correlate attack indicators and identify compromise attempts even before formal CVE-specific detection rules are available.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82447. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation