Summary banks /tmp/rce_banks_exec').read() }}") p.text() ` `bash ls -l /tmp/rce_banks_exec -rw-rw-r-1 ak ak 4 Apr 27 15:36 /tmp/rce_banks_exec ` Impact Applications that allow end-users to supply or customize prompt tem…
| CVE ID | CVE-2026-44209 |
| Vendor | pip |
| Affected Product | banks |
| Vulnerability Type | Vulnerability |
| CVSS Score | 7.5 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
#
banks /tmp/rce_banks_exec').read() }}")p.text() ` `bash ls -l /tmp/rce_banks_exec
`
(PR #74) by switching to jinja2.sandbox.SandboxedEnvironment, which blocks the dunder attribute traversal chain this exploit relies on. Developers on banks <= 2.4.1 should upgrade to 2.4.2 and avoid passing untrusted user input as the template argument to Prompt()`.Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.