{"id":"CVE-2026-53598","aliases":["GHSA-wxhm-2mq7-7697","PYSEC-2026-3538"],"url":"https://o3.security/vulnerability/CVE-2026-53598","summary":"Prompty: Arbitrary File Read via ${file:path} Reference Expansion","details":"Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2.","published":"2026-07-16T14:59:01.797Z","modified":"2026-08-12T03:51:44.470452051Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01286,"percentile":0.68126,"asOf":"2026-08-30"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"prompty","fixedVersion":"2.0.0-beta.2"},{"ecosystem":"npm","name":"@prompty/core","fixedVersion":"2.0.0-beta.2"},{"ecosystem":"NuGet","name":"Prompty.Core","fixedVersion":"2.0.0-beta.2"},{"ecosystem":"PyPI","name":"prompty","fixedVersion":"2.0.0b2"}],"fix":{"url":"https://github.com/microsoft/prompty/commit/88ac9948d7d37995edbb2f6d36913436626c39e1","label":"microsoft/prompty@88ac994"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53598.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/prompty/security/advisories/GHSA-wxhm-2mq7-7697"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53598"},{"type":"FIX","url":"https://github.com/microsoft/prompty/commit/88ac9948d7d37995edbb2f6d36913436626c39e1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.470452051Z"}}