CVE-2026-71492: Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled ...
Added to the CISA Known Exploited Vulnerabilities catalog on 20 Aug 2026. Vendor: AI/ML. Product: LLM.
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation...
Required action: Review and patch if applicable to your AI infrastructure.