prompty vulnerabilities
CVEs whose affected-version data names the prompty package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-73299Critical· 10.0Prompty is a markdown file format (.prompty) for LLM prompts
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…
▾ Midnightmicrosoft · promptyEPSS 1.2%via NVD
CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
▾ Twilightprompty · promptyEPSS 1.3%via GHSA