CVE-2026-15519 LOW

CVE-2026-15519: usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere

Vendor Usestrix
Product strix
Weakness CWE-829 · Inclusion from untrusted sphere
Published July 13, 2026
Last update July 13, 2026

CVSS base score

2.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the file system_prompt.jinja of the component PyPI Handler. Performing a manipulation results in inclusion of functionality from untrusted control sphere. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is reported as difficult. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Key dates

02Disclosure timeline

July 13, 2026 CVE published
July 13, 2026 Record updated