banks
LLM prompt language based on Jinja. Banks provides tools and functions to build prompts text and chat messages from generic blueprints. It allows attaching metadata to prompts to ease their management, and versioning is first-class citizen. Banks provides ways to store prompts on disk along with their metadata.
Activity
- Latest release
- 4d ago
- Total releases
- 38
- Cadence
- ~13 days
- Last 12 months
- 9
Reach
- Stars
- 129
Details
- License
- MIT
- First release
- Jun 04, 2023
| Version | Released | |
|---|---|---|
2.5.1
patch
| ||
2.5.0
minor
| ||
2.4.5
patch
| ||
2.4.4
patch
1 CVE
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.3
patch
1 CVE
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.2
patch
1 CVE
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
2.4.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.3.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.3
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.2
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0
major
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.8.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.7.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.6.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.5.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.4.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.3.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.2.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.1.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
1.0.0
major
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.6.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.5.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.4.1
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.3.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.2.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.1
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.1.0
minor
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.3
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.2
patch
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.0.1
initial
2 CVEs
CVE-2026-71492
PYSEC-2026-3810
GHSA-x8wg-4xgc-vr54
Sep 10, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
High
Network
Low
Low
None
Summary
Details
Two failure modes:
The poisoned Proof of Concept
Output (verified on
Negative control: with a benign ImpactArbitrary file write at an attacker-chosen path with attacker-controlled bytes, scoped to whatever the application process can write to. The Realistic threat model: any "prompt management" service that exposes prompt creation through an authenticated API and forwards user-supplied Suggested FixReject obviously dangerous names early and verify the resulting path stays under the registry root after canonicalization:
The same enforcement should run inside Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 23 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
Fixed in
2.4.5
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-44209
PYSEC-2026-2390
GHSA-gphh-9q3h-jgpp
Jul 13, 2026
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
7.5
/ 10
High
Network
High
None
Required
Unchanged
High
High
High
Summary
This is a vulnerability in how Vulnerable Code
Attack ScenarioAn application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to
Proof of ConceptSetup:
PoC script:
Confirmed output:
ImpactApplications that allow end-users to supply or customize prompt templates are at risk of full Remote Code Execution, including arbitrary command execution, data exfiltration, and server compromise. FixFixed in Developers on Resources
Affected versions
0.0.1
0.0.2
0.0.3
0.1.0
0.1.1
0.2.0
0.3.0
0.3.1
0.4.1
0.5.0
0.6.0
1.0.0
+ 20 more Show less
1.1.0
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.6.0
1.6.1
1.7.0
1.7.1
1.8.0
2.0.0
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0
2.3.0
2.4.0
2.4.1
Fixed in
2.4.2
References Updated Jul 13, 2026 · Source: OSV.dev |