CVE-2025-49619 affects Skyvern through version 0.1.85. The vulnerability is a server-side template injection (SSTI) issue in the Prompt field of workflow blocks, including the Navigation v2 Block. Improper sanitization of Jinja2 template input allows an authenticated user to supply crafted template expressions that are evaluated on the server. Because attacker-controlled Jinja2 expressions are processed server-side, the flaw can be leveraged to achieve blind remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module targeting a server-side template injection (SSTI) vulnerability (CVE-2025-49619) in Skyvern versions 0.1.84 and below. The exploit requires a valid API key for the Skyvern instance. The module works by uploading a malicious workflow via the '/api/v1/workflows' endpoint, embedding a Python-based SSTI payload that executes arbitrary system commands. The workflow is then triggered via the '/api/v1/workflows/<workflow_id>/run' endpoint, resulting in remote code execution on the target Linux system. The code is written in Ruby and follows standard Metasploit module structure, utilizing the HttpClient mixin for network communication. The exploit is operational, requiring some configuration (API key) but providing reliable code execution if the target is vulnerable.
This repository is a proof-of-concept exploit for CVE-2025-49619, targeting Skyvern versions prior to 0.1.85. The exploit leverages a server-side template injection (SSTI) vulnerability in the Skyvern Workflow Editor, allowing an attacker with a valid API key to inject a malicious Jinja2 template. This template is rendered server-side, resulting in blind remote code execution. The main exploit script (exploit.py) automates the process: it creates a malicious workflow via the Skyvern API and then executes it, causing the server to connect back to the attacker's machine with a reverse shell. The attacker must provide the target server URL, a valid API key, and their own IP/port for the reverse shell. The repository includes a JSON file (exploit-workflow.json) that mirrors the payload structure, a README with usage instructions, and a requirements.txt listing dependencies. The exploit is operational and provides a working reverse shell if the target is vulnerable and properly configured.
7 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.