{"id":"CVE-2026-71492","aliases":["GHSA-x8wg-4xgc-vr54","PYSEC-2026-3810"],"url":"https://o3.security/vulnerability/CVE-2026-71492","summary":"Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root","details":"Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation. Relative traversal such as ../victim/foo and an absolute Prompt.name can escape or discard the configured registry root, while overwrite=True permits replacement of existing target files. The poisoned name is persisted in index.json and reconstructed by _load(), allowing the out-of-root path to survive later registry loads. An application that forwards request data into these fields can therefore write Prompt.raw bytes to attacker-chosen paths writable by the application process. This issue is fixed in version 2.4.5.","published":"2026-08-20T16:13:55.578Z","modified":"2026-09-10T12:25:29.001076918Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"banks","fixedVersion":"2.4.5"}],"fix":{"url":"https://github.com/masci/banks/commit/a215f6d779966945c56e0af5abed1ae5916fd9d3","label":"masci/banks@a215f6d"},"references":[{"type":"WEB","url":"https://github.com/masci/banks/releases/tag/v2.4.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71492.json"},{"type":"ADVISORY","url":"https://github.com/masci/banks/security/advisories/GHSA-x8wg-4xgc-vr54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71492"},{"type":"FIX","url":"https://github.com/masci/banks/commit/a215f6d779966945c56e0af5abed1ae5916fd9d3"},{"type":"FIX","url":"https://github.com/masci/banks/pull/77"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T12:25:29.001076918Z"}}