mitsuhiko: template engines like jinja2 are unsafe for untrusted input without OS-level isolation
mitsuhiko · x · 2026-10-10
Adding his core argument to the codemode isolation thread, mitsuhiko says that from his experience maintaining jinja2/minijinja, such template engines are not safe to run on fully untrusted input without also putting an OS-level boundary between execution contexts—explaining why he found basic shared-worker isolation insufficient.
Related event: mitsuhiko warns AST interpreters alone are not enough to sandbox agent code(8 posts)→
More from coding & agent
- Indie dev builds a GT5-grade browser racing sim in ThreeJS, tuned to IMSA GT3 rulebook — AIandDesign · 2026-10-10
- Agent-built system hits 2,242 tok/s on AMD MI300As, 2.33× faster than SGLang in 105 hours — bariskasikci · 2026-10-10
- Seroter's Daily Reads: Agent-Friendly APIs, LLM Judges, and Ambient Quality Agents — rseroter · 2026-10-10
- Steve Yegge: Claude just reads the binary when it wants to know how closed-source Rex works — Steve_Yegge · 2026-10-10
- YC hosts an agent-first hackathon in San Francisco, sponsored by Supabase — ycombinator · 2026-10-10
- Running a fleet of long-horizon LLM agents: 9 keep-alive patterns and 5 unsolved problems — milkygirl21 · 2026-10-10