CVE-2026-73299
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.
| CWE | CWE-94 CWE-1336 |
| Vendor | microsoft |
| Product | prompty |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Aug 12, 2026 |
| Last Updated | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for microsoft prompty
Be the first to know when new critical vulnerabilities affecting microsoft prompty are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
microsoft / prompty
< 0.1.5 >= 2.0.0-alpha.1, < 2.0.0-beta.5
References
github.com: https://github.com/microsoft/prompty/security/advisories/GHSA-w28w-gp39-m4p6 github.com: https://github.com/microsoft/prompty/pull/404 github.com: https://github.com/microsoft/prompty/pull/405 github.com: https://github.com/microsoft/prompty/commit/e4a0ebf49e3a78d5d7796c8480bf9a4f0c54d19e github.com: https://github.com/microsoft/prompty/commit/f5c57c94a0990cca79d095c3daab661b4b1fb89f github.com: https://github.com/microsoft/prompty/tree/typescript/2.0.0-beta.5