๐Ÿ” CVE Alert

CVE-2026-107716

UNKNOWN 0.0

Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.

CWE CWE-22 CWE-59
Vendor masci
Product banks
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for masci banks

Be the first to know when new unknown vulnerabilities affecting masci banks are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

masci / banks
< 2.5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/masci/banks/security/advisories/GHSA-556j-vv39-8rqv github.com: https://github.com/masci/banks/pull/79 github.com: https://github.com/masci/banks/commit/23ed13e50b4e217693fa5f9c30943fac8a41582f github.com: https://github.com/masci/banks/releases/tag/v2.5.1