Back

HIGH

Prompty: Arbitrary File Read via ${file:path} Reference Expansion

Published Jul 16, 2026

Description

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 16, 2026
Updated Jul 17, 2026
Reserved Jun 9, 2026
CISA Vulnrichment
Updated Jul 17, 2026
NVD
Status Deferred
Modified Jul 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-WXHM-2MQ7-7697