Summary Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that the resolved path stayed within an authorized directory. An attacker-controlled prompt file could use path traversal…
| CVE ID | CVE-2026-53598 |
| Vendor | Unknown Vendor |
| Affected Product | Unknown Product |
| Vulnerability Type | Security Vulnerability |
| CVSS Score | 7.5 (HIGH) |
| EPSS Score | 1.1% probability of exploitation in the next 30 days |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | Pending Vendor Disclosure |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex) |
#
Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that the resolved path stayed within an authorized directory. An attacker-controlled prompt file could use path traversal or an absolute path to cause the host application to read files accessible to the process.
#
prompty versions <= 2.0.0b1; fixed in 2.0.0b2@prompty/core versions <= 2.0.0-beta.1; fixed in 2.0.0-beta.2prompty versions <= 2.0.0-beta.1; fixed in 2.0.0-beta.2Prompty.Core versions <= 2.0.0-beta.1; fixed in 2.0.0-beta.2#
Applications that load untrusted .prompty files, user-provided prompt paths, or prompt bundles from less-trusted locations could disclose local files available to th
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.