diff --git a/CHANGELOG.md b/CHANGELOG.md index cc744394..d99d7ad0 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -13,6 +13,8 @@ Status of the `main` branch. Changes prior to the next official version change w - Project activation errors are now reported to the client in Serena's system prompt, instead of failures being visible only in the log. This applies both to a failed activation of an explicitly given project and to a failed `--project-from-cwd` auto-detection (#1773). + - Security: Use sandboxed environment for prompt templating, preventing attackers from using custom prompts to + execute commands in an uncontrolled manner * CLI: - Fix: `start-mcp-server` help text for `--project-from-cwd` falsely promised a fallback to the CWD, which was diff --git a/src/interprompt/jinja_template.py b/src/interprompt/jinja_template.py index 32220155..85dec9fe 100644 --- a/src/interprompt/jinja_template.py +++ b/src/interprompt/jinja_template.py @@ -4,6 +4,7 @@ import jinja2 import jinja2.meta import jinja2.nodes import jinja2.visitor +from jinja2.sandbox import SandboxedEnvironment from interprompt.util.class_decorators import singleton @@ -19,7 +20,7 @@ class _JinjaEnvProvider: def get_env(self) -> jinja2.Environment: if self._env is None: - self._env = jinja2.Environment() + self._env = SandboxedEnvironment() return self._env