What happened
Verified via NVD REST API (published 2026-10-08): Banks' DirectoryPromptRegistry prior to 2.5.1 does not reject symbolic links for index.json or discovered .jinja prompt files (CWE-22/CWE-59), so _scan()/get() can follow a link outside the registry root and disclose a file, while set()/_save()/_load() can read or overwrite an external link target.
Why it matters
The prompt registry is the input surface of an LLM application; a file read/overwrite primitive on it lets an attacker exfiltrate sensitive files or tamper with the exact prompts the model runs against — a supply-chain/context-integrity attack on the prompt layer.
Attack vector
An attacker who can place files/symlinks in the registry directory (e.g. via an upload/extraction feature) points an index.json or .jinja prompt file symlink at an arbitrary path; the registry follows it, disclosing or overwriting files outside the registry root when prompts are loaded or saved.
Affected systems
masci/banks < 2.5.1 (LLM prompt template library with directory prompt registry)
Mitigation
Upgrade to banks 2.5.1; advisory GHSA-556j-vv39-8rqv. Validate that registry entries are canonical files within the registry root (reject symlinks).