Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-556j-vv39-8rqv | Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry |
Thu, 08 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Masci
Masci banks |
|
| Vendors & Products |
Masci
Masci banks |
Thu, 08 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1. | |
| Title | Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:33:13.391Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107716
No data.
Status : Deferred
Published: 2026-10-08T22:17:27.323
Modified: 2026-10-08T22:17:27.480
Link: CVE-2026-107716
No data.
OpenCVE Enrichment
Updated: 2026-10-08T22:30:18Z
Github GHSA