MCPA-2026-0047
highpath-traversal
Prompty file-reference expansion allows arbitrary file read (CVE-2026-53598)
Prompty loaders expanded ${file:...} references in .prompty frontmatter without confining the resolved path, so an attacker-controlled prompt file can use path traversal or absolute paths to read any file accessible to the host process. Affects PyPI prompty (<= 2.0.0b1, fixed 2.0.0b2), npm @prompty/core (<= 2.0.0-beta.1, fixed 2.0.0-beta.2), and NuGet Prompty.Core (<= 2.0.0-beta.1, fixed 2.0.0-beta.2); a Rust crate is also affected (outside this database's ecosystems).
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | prompty | >= 0, < 2.0.0b2 |
| npm | @prompty/core | >= 0, < 2.0.0-beta.2 |
| nuget | Prompty.Core | >= 0, < 2.0.0-beta.2 |
Identifiers
CVE-2026-53598GHSA-wxhm-2mq7-7697CWE-22CWE-200
References
- advisory https://github.com/advisories/GHSA-wxhm-2mq7-7697
- advisory https://github.com/microsoft/prompty/security/advisories/GHSA-wxhm-2mq7-7697
- web https://nvd.nist.gov/vuln/detail/CVE-2026-53598
Timeline
- Published: 2026-07-17