prompty has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was July 2026 with 3. The median CVSS is 8.8 (high), with 1 rated critical. Most affected products: @prompty/core (2), prompty (1).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- @prompty/core 2
- prompty 1
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer55CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion42CVE-2026-53597HighPrompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader41
prompty vulnerabilities
CVEs affecting prompty, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
▾ Midnightprompty · @prompty/corevia GHSA
CVE-2026-53598High· 7.5Prompty: Arbitrary file read via file reference expansion
Prompty: Arbitrary file read via file reference expansion
▾ Twilightprompty · promptyEPSS 1.3%via GHSA
CVE-2026-53597HighPrompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
▾ Twilightprompty · @prompty/coreEPSS 0.97%via GHSA