Vulnerability  ·  2026-10-10

Banks LLM prompt registry follows symlinks out of the prompt directory for file read/overwrite (CVSS 7.3)

VulnerabilityMedium impactGlobalCVE-2026-107716
Verified via NVD REST API (published 2026-10-08): Banks' DirectoryPromptRegistry prior to 2.5.1 does not reject symbolic links for index.json or discovered .jinja prompt files (CWE-22/CWE-59), so _scan()/get() can follow a link outside the registry root and disclose a file, while set()/_save()/_load() can read or overwrite an external link target.
The prompt registry is the input surface of an LLM application; a file read/overwrite primitive on it lets an attacker exfiltrate sensitive files or tamper with the exact prompts the model runs against — a supply-chain/context-integrity attack on the prompt layer.
An attacker who can place files/symlinks in the registry directory (e.g. via an upload/extraction feature) points an index.json or .jinja prompt file symlink at an arbitrary path; the registry follows it, disclosing or overwriting files outside the registry root when prompts are loaded or saved.
masci/banks < 2.5.1 (LLM prompt template library with directory prompt registry)
Upgrade to banks 2.5.1; advisory GHSA-556j-vv39-8rqv. Validate that registry entries are canonical files within the registry root (reject symlinks).
NVD CVE-2026-107716GitHub Security Advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →