PT-2026-60485 · Prompty · Prompty
CVE-2026-53598
·
Published
2026-07-16
·
Updated
2026-07-23
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Prompty versions prior to 2.0.0-beta.2
Description
Prompty loaders fail to properly validate the resolution of
${file:...} references within .prompty frontmatter. This lack of enforcement allows the resolution of paths outside the intended prompt directory or allowed roots, enabling an attacker to read local files using absolute paths, directory traversal (using ..), or symlink escapes.Recommendations
Update to version 2.0.0-beta.2.
Exploit
Fix
Information Disclosure
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prompty