CVE-2026-73299: Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaSc...
Added to the CISA Known Exploited Vulnerabilities catalog on 12 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 10.
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype propert...
Required action: Review and patch if applicable to your AI infrastructure.