Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage — it only impacts self-hosted or managed Agenta platform deployments. Version 0.86.8 contains a fix for the issue.
History

Mon, 02 Mar 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Agentatech
Agentatech agenta
CPEs cpe:2.3:a:agentatech:agenta:*:*:*:*:*:*:*:*
Vendors & Products Agentatech
Agentatech agenta

Fri, 27 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Agenta-ai
Agenta-ai agenta
Vendors & Products Agenta-ai
Agenta-ai agenta

Thu, 26 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Description Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage — it only impacts self-hosted or managed Agenta platform deployments. Version 0.86.8 contains a fix for the issue.
Title Agenta's Server-Side Template Injection (SSTI) via custom evaluator Jinja2 templates allows RCE
Weaknesses CWE-1336
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-26T01:39:09.997Z

Updated: 2026-02-26T19:29:04.883Z

Reserved: 2026-02-25T03:24:57.792Z

Link: CVE-2026-27961

cve-icon Vulnrichment

Updated: 2026-02-26T19:28:59.844Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-26T02:16:23.483

Modified: 2026-03-02T18:40:39.127

Link: CVE-2026-27961

cve-icon Redhat

No data.