CVE-2026-61536: Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resol...
Added to the CISA Known Exploited Vulnerabilities catalog on 30 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.
Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to obtain the callab...
Required action: Review and patch if applicable to your AI infrastructure.