---
id: CVE-2026-107717
title: Banks generates meaningful LLM prompts using a simple template language
summary: >-
  Banks generates meaningful LLM prompts using a simple template language. Prior
  to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of
  rendered template output as ChatMessage JSON. When an application renders
  untrusted dat…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-20
vendor: banks
product: banks
affected:
  - banks <= 2.4.5
patched:
  - banks 2.5.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:27.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107717'
references:
  - url: >-
      https://github.com/masci/banks/commit/02172b816fb84f6a824cc09a8aca7416f53c12cb
    label: security-advisories@github.com
  - url: 'https://github.com/masci/banks/pull/78'
    label: security-advisories@github.com
  - url: 'https://github.com/masci/banks/releases/tag/v2.5.0'
    label: security-advisories@github.com
  - url: 'https://github.com/masci/banks/security/advisories/GHSA-hmq2-7hp6-7crh'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-hmq2-7hp6-7crh'
tags:
  - nvd
  - ghsa
  - pip
aliases:
  - GHSA-hmq2-7hp6-7crh
ecosystem: pip
ingestedAt: '2026-10-08T22:11:53.870Z'
---

## Overview

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107717)

Affected packages:

- `banks <= 2.4.5`

Patched in:

- `banks 2.5.0`

Source: https://github.com/advisories/GHSA-hmq2-7hp6-7crh
