CVE-2026-107716 PUBLISHED

Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry

Assigner: GitHub_M
Reserved: 08.10.2026 Published: 08.10.2026 Updated: 09.10.2026

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS Score: 7.3

Product Status

Vendor masci
Product banks
Versions
  • Version < 2.5.1 is affected

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE