Impact
Polyaxon versions up to 2.16.4 render operation specification fields with an unsandboxed Jinja2 environment during server‑side run preparation. This flaw allows authenticated users to inject Jinja2 expressions that are evaluated in the scheduler process context, giving an attacker the ability to run arbitrary operating system commands. The attack can exploit fields such as queue, namespace, conditions, presets, or dependencies, potentially exposing database credentials and service tokens.
Affected Systems
All deployments of Polyaxon using versions 2.16.4 or earlier are affected. The vulnerability impacts the server component that prepares jobs for execution, and any authenticated user who can submit runs can exploit this flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. Exploitation requires authentication and access to the Polyaxon server, so the risk is primarily to internal users or compromised accounts. The EPSS score of 0.00476 indicates a very low probability of exploitation in the current state, though the flaw is not listed in the CISA KEV catalog. Nevertheless, the high CVSS score and the ability to execute code in the scheduler process represent a serious internal threat.
OpenCVE Enrichment