PT-2026-108246 · Banks · Banks

CVE-2026-107717

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Banks versions prior to 2.5.0
Description The Prompt.chat messages() function attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data, attacker-controlled JSON can be interpreted as a privileged message because the ChatMessage.role variable accepts arbitrary strings. This allows an attacker to inject system, assistant, or tool messages, which can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This is a chat role injection issue where user-controlled content crosses the boundary into developer-controlled chat message structure.
Recommendations Update Banks to version 2.5.0. As a temporary workaround, avoid rendering untrusted user input directly within prompt templates used by the Prompt.chat messages() function.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107717
GHSA-HMQ2-7HP6-7CRH

Affected Products

Banks