PT-2026-108246 · Banks · Banks
CVE-2026-107717
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Banks versions prior to 2.5.0
Description
The
Prompt.chat messages() function attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data, attacker-controlled JSON can be interpreted as a privileged message because the ChatMessage.role variable accepts arbitrary strings. This allows an attacker to inject system, assistant, or tool messages, which can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This is a chat role injection issue where user-controlled content crosses the boundary into developer-controlled chat message structure.Recommendations
Update Banks to version 2.5.0.
As a temporary workaround, avoid rendering untrusted user input directly within prompt templates used by the
Prompt.chat messages() function.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Banks