CVE-2026-107716: Masci Banks

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.

Affected products

  • Masci Banks: before 2.5.1 (fixed in 2.5.1)

Published 2026-10-08. Last modified 2026-10-09.