{"id":"CVE-2026-107716","title":"Banks generates meaningful LLM prompts using a simple template language","summary":"Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where …","severity":"medium","cwe":["CWE-22","CWE-59"],"vendor":"banks","product":"banks","affected":["banks <= 2.5.0"],"patched":["banks 2.5.1"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:27.480","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107716","references":[{"url":"https://github.com/masci/banks/commit/23ed13e50b4e217693fa5f9c30943fac8a41582f","label":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/pull/79","label":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/releases/tag/v2.5.1","label":"security-advisories@github.com"},{"url":"https://github.com/masci/banks/security/advisories/GHSA-556j-vv39-8rqv","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-556j-vv39-8rqv"},{"url":"https://github.com/masci/banks"}],"tags":["nvd","ghsa","pip","osv"],"aliases":["GHSA-556j-vv39-8rqv"],"ecosystem":"pip","ingestedAt":"2026-10-08T22:11:53.869Z","slug":"CVE-2026-107716","body":"## Overview\n\nBanks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-107716)\n\nAffected packages:\n\n- `banks <= 2.5.0`\n\nPatched in:\n\n- `banks 2.5.1`\n\nSource: https://github.com/advisories/GHSA-556j-vv39-8rqv","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}