Impact
A flaw in the usestrix strix package allows the system_prompt.jinja file of the PyPI Handler component to include functionality originating from an untrusted control sphere. The vulnerability is classified as CWE‑829, indicating that operations are performed without proper restriction. When triggered, the application may execute unintended code or alter its expected behavior, potentially compromising integrity or availability.
Affected Systems
The issue is present in usestrix strix versions up to and including 1.0.2. No other versions or related products are identified as affected.
Risk and Exploitability
The CVSS score of 2.3 indicates low overall severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the description states the attack can be carried out remotely and the complexity is reported as high with exploitability described as difficult, the likely attack vector is remote. The vendor has not published a fix, so the exposure remains pending a remediation.
OpenCVE Enrichment