Use sandboxed environment for jinja2 template rendering

This prevents attackers from exploiting jinja's code execution mechanisms
via custom prompts (e.g. mode inclusion from local file)
This commit is contained in:
Dominik Jain committed 2026-08-05 14:14:56 +02:00
1 parent b8fd8a936a
commit 81fb5203f9
2 files changed
+4 -1

No files matched your search

+2
View File
@@ -13,6 +13,8 @@ Status of the `main` branch. Changes prior to the next official version change w
- Project activation errors are now reported to the client in Serena's system prompt, instead of failures
being visible only in the log. This applies both to a failed activation of an explicitly given project and to a
failed `--project-from-cwd` auto-detection (#1773).
- Security: Use sandboxed environment for prompt templating, preventing attackers from using custom prompts to
execute commands in an uncontrolled manner
* CLI:
- Fix: `start-mcp-server` help text for `--project-from-cwd` falsely promised a fallback to the CWD, which was
+2 -1
View File
@@ -4,6 +4,7 @@ import jinja2
import jinja2.meta
import jinja2.nodes
import jinja2.visitor
from jinja2.sandbox import SandboxedEnvironment
from interprompt.util.class_decorators import singleton
@@ -19,7 +20,7 @@ class _JinjaEnvProvider:
def get_env(self) -> jinja2.Environment:
if self._env is None:
self._env = jinja2.Environment()
self._env = SandboxedEnvironment()
return self._env