Description
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-13
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the usestrix strix package allows the system_prompt.jinja file of the PyPI Handler component to include functionality originating from an untrusted control sphere. The vulnerability is classified as CWE‑829, indicating that operations are performed without proper restriction. When triggered, the application may execute unintended code or alter its expected behavior, potentially compromising integrity or availability.

Affected Systems

The issue is present in usestrix strix versions up to and including 1.0.2. No other versions or related products are identified as affected.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity, and the EPSS score of <1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the description states the attack can be carried out remotely and the complexity is reported as high with exploitability described as difficult, the likely attack vector is remote. The vendor has not published a fix, so the exposure remains pending a remediation.

Generated by OpenCVE AI on July 31, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor’s release notes or website for an official patch for any version newer than 1.0.2 and upgrade when it becomes available.
  • If a patch is not yet available, disable or remove the system_prompt.jinja feature from the PyPI Handler or restrict its use to trusted sources only.
  • Validate all inputs to the PyPI Handler to ensure only trusted template files are processed and reject unverified content.
  • Monitor application logs for unexpected template inclusions or execution patterns, and implement additional hardening such as sandboxing or access controls around the PyPI Handler.

Generated by OpenCVE AI on July 31, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere
First Time appeared Usestrix
Usestrix strix
Weaknesses CWE-829
CPEs cpe:2.3:a:usestrix:strix:*:*:*:*:*:*:*:*
Vendors & Products Usestrix
Usestrix strix
References
Metrics cvssV2_0

{'score': 5.1, 'vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-13T15:25:15.599Z

Reserved: 2026-07-12T11:16:58.125Z

Link: CVE-2026-15519

cve-icon Vulnrichment

Updated: 2026-07-13T15:25:09.406Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:30:16Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere