@prompty/core vulnerabilities
CVEs whose affected-version data names the @prompty/core package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
▾ Midnightprompty · @prompty/corevia GHSA
CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
▾ Twilightprompty · promptyEPSS 1.3%via GHSA
CVE-2026-53597HighPrompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
▾ Twilightprompty · @prompty/coreEPSS 0.97%via GHSA