A high-severity vulnerability, CVE-2026-53598 with a CVSS score of 7.5, exists in prompty loaders due to arbitrary file read via file reference expansion. This flaw allows an attacker-controlled prompt file to use path traversal or an absolute path to cause the host application to read files accessible to the process, potentially disclosing local files available to the application process when expanded values are logged, returned, or otherwise exposed. The vulnerability affects applications that load untrusted.prompty files, user-provided prompt paths, or prompt bundles from less-trusted locations. Affected versions include those prior to 2.0.0b1 and 2.0.0-beta.1.
The following reports contain further technical details:[/subscribe_to_unlock_form]
A high-severity vulnerability, CVE-2026-53598 with a CVSS score of 7.5, exists in prompty loaders due to arbitrary file read via file reference expansion. This flaw allows an attacker-controlled prompt file to use path traversal or an absolute path to cause the host application to read files accessible to the process, potentially disclosing local files available to the application process when expanded values are logged, returned, or otherwise exposed. The vulnerability affects applications that load untrusted.prompty files, user-provided prompt paths, or prompt bundles from less-trusted locations. Affected versions include those prior to 2.0.0b1 and 2.0.0-beta.1.
The following reports contain further technical details:[emaillocker id="1283"]
[/emaillocker]