Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-31020: DocsGPT allows attacker to run code via custom prompts

CVE-2026-31020 · published today
Summary

DocsGPT versions up to 0.15 let users create their own chatbot prompts, but the software does not check or protect the content of those prompts. This means a remote attacker could insert special code that the server will execute, giving them full control of the system. Upgrade to a newer version or disable the custom prompt feature until the issue is patched.

Original advisory text
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied p...
In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An unauthenticated attacker can inject malicious template expressions, leading to a server-side template injection (SSTI) vulnerability that can be exploited to achieve full remote code execution (RCE).
Severity
9.8 Critical
Type
CWE-94Code Injection
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-31020 · MITRE
Monitor software like this
Free during beta