CVE-2026-71492: Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled ...

Added to the CISA Known Exploited Vulnerabilities catalog on 20 Aug 2026. Vendor: AI/ML. Product: LLM.

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or containment validation...

Required action: Review and patch if applicable to your AI infrastructure.