Skip to content

MCPA-2026-0046

highrce-vectors

Prompty TypeScript loader executes JavaScript frontmatter in .prompty files (CVE-2026-53597)

The TypeScript Prompty loader (@prompty/core) used gray-matter without disabling executable frontmatter engines, so a .prompty file with a ---js frontmatter block executes arbitrary JavaScript during prompt loading. Any application loading attacker-controlled prompt assets is exposed. Affects the @prompty/core npm 2.0 prerelease line (>= 2.0.0-alpha.1); fixed in 2.0.0-beta.3.

Affected packages

EcosystemPackageAffected versions
npm@prompty/core
>= 2.0.0-alpha.1, < 2.0.0-beta.3

Identifiers

CVE-2026-53597GHSA-c4gh-rv8h-q9vwCWE-94

References

Timeline

  • Published: 2026-07-17

← All advisories