Skip to content

fix: adding safeguard to prevent callable within prompt templates - #12937

Open
davidsbatista wants to merge 3 commits into
mainfrom
fix/jinj2sandbox-refuse-callables-inside-templates
Open

davidsbatista wants to merge 3 commits into
mainfrom
fix/jinj2sandbox-refuse-callables-inside-templates

Conversation

@davidsbatista

Copy link
Copy Markdown
Contributor

Proposed Changes:

A template with a Document or ByteStream in context could call Document.from_dict(), ByteStream.to_file(), ByteStream.from_file_path(), or Secret.resolve_value() to write/read arbitrary files or read environment variables, since these methods are defined in haystack.dataclasses/haystack.utils.auth, not on the module denylist.

Added a second check in is_safe_callable that denies any callable whose __module__ starts with haystack.dataclasses or haystack.utils.auth.

How did you test it?

Added unit tests in test/utils/test_jinja2_sandbox.py:

  • attribute access on a Document still works
  • Document.from_dict() → ByteStream.to_file() is blocked
  • ByteStream.from_file_path() is blocked
  • Secret.resolve_value() is blocked

Checklist

  • I have read the contributors guidelines and the code of conduct.
  • I have updated the related issue with new insights and changes.
  • I have added unit tests and updated the docstrings.
  • I've used one of the conventional commit types for my PR title: fix:.
  • I have documented my code.
  • I have added a release note file.
  • I have run pre-commit hooks and fixed any issue.

@vercel

vercel Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
haystack-docs Ignored Ignored Preview Sep 25, 2026 2:15pm UTC

Request Review

@github-actions github-actions Bot added topic:tests type:documentation Improvements on the docs labels Sep 24, 2026
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Coverage report

Click to see where and how coverage changed

FileStatementsMissingCoverageCoverage
(new stmts)
Lines missing
  haystack/utils
  jinja2_sandbox.py
Project Total  

This report was generated by python-coverage-comment-action

@davidsbatista
davidsbatista marked this pull request as ready for review September 24, 2026 16:05
@davidsbatista
davidsbatista requested a review from a team as a code owner September 24, 2026 16:05
@anakin87
anakin87 removed the request for review from a team September 25, 2026 14:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

topic:tests type:documentation Improvements on the docs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant