CRITICAL
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Published Aug 12, 2026
10.0
CRITICALCVSS 3.1
EPSS 1.78%
Description
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.
Affected products
-
Affected
- < 0.1.5
- ≥ 2.0.0-alpha.1, < 2.0.0-beta.5
No data.
No data.
No Red Hat product state for this CVE.
@prompty/core
npm
Introduced 0 Fixed 0.1.5@prompty/core
npm
Introduced 2.0.0-alpha.1 Fixed 2.0.0-beta.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @prompty/core | 0 | 0.1.5 |
| npm | @prompty/core | 2.0.0-alpha.1 | 2.0.0-beta.5 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57382 Advisory
- https://github.com/microsoft/prompty/commit/e4a0ebf49e3a78d5d7796c8480bf9a4f0c54d19e x_refsource_MISC
- https://github.com/microsoft/prompty/commit/f5c57c94a0990cca79d095c3daab661b4b1fb89f x_refsource_MISC
- https://github.com/microsoft/prompty/pull/404 x_refsource_MISC
- https://github.com/microsoft/prompty/pull/405 x_refsource_MISC
- https://github.com/microsoft/prompty/security/advisories/GHSA-w28w-gp39-m4p6 x_refsource_CONFIRM
- https://github.com/microsoft/prompty/tree/typescript/2.0.0-beta.5 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-57382 | Advisory | |
| https://github.com/microsoft/prompty/commit/e4a0ebf49e3a78d5d7796c8480bf9a4f0c54d19e | x_refsource_MISC | |
| https://github.com/microsoft/prompty/commit/f5c57c94a0990cca79d095c3daab661b4b1fb89f | x_refsource_MISC | |
| https://github.com/microsoft/prompty/pull/404 | x_refsource_MISC | |
| https://github.com/microsoft/prompty/pull/405 | x_refsource_MISC | |
| https://github.com/microsoft/prompty/security/advisories/GHSA-w28w-gp39-m4p6 | x_refsource_CONFIRM | |
| https://github.com/microsoft/prompty/tree/typescript/2.0.0-beta.5 | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 12, 2026
Updated Aug 12, 2026
Reserved Aug 11, 2026
Link CVE-2026-73299
CISA Vulnrichment
Updated Aug 12, 2026
Red Hat
No data
GitHub
No data