Skip to content

MCPA-2026-0047

highpath-traversal

Prompty file-reference expansion allows arbitrary file read (CVE-2026-53598)

Prompty loaders expanded ${file:...} references in .prompty frontmatter without confining the resolved path, so an attacker-controlled prompt file can use path traversal or absolute paths to read any file accessible to the host process. Affects PyPI prompty (<= 2.0.0b1, fixed 2.0.0b2), npm @prompty/core (<= 2.0.0-beta.1, fixed 2.0.0-beta.2), and NuGet Prompty.Core (<= 2.0.0-beta.1, fixed 2.0.0-beta.2); a Rust crate is also affected (outside this database's ecosystems).

Affected packages

EcosystemPackageAffected versions
pypiprompty
>= 0, < 2.0.0b2
npm@prompty/core
>= 0, < 2.0.0-beta.2
nugetPrompty.Core
>= 0, < 2.0.0-beta.2

Identifiers

CVE-2026-53598GHSA-wxhm-2mq7-7697CWE-22CWE-200

References

Timeline

  • Published: 2026-07-17

← All advisories