CVE-2026-53598: Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths st...

Added to the CISA Known Exploited Vulnerabilities catalog on 16 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to re...

Required action: Review and patch if applicable to your AI infrastructure.