Threat Advisory

Prompty Flaw Allows Arbitrary File Read via Path Traversal

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-53598 with a CVSS score of 7.5, exists in prompty loaders due to arbitrary file read via file reference expansion. This flaw allows an attacker-controlled prompt file to use path traversal or an absolute path to cause the host application to read files accessible to the process, potentially disclosing local files available to the application process when expanded values are logged, returned, or otherwise exposed. The vulnerability affects applications that load untrusted.prompty files, user-provided prompt paths, or prompt bundles from less-trusted locations. Affected versions include those prior to 2.0.0b1 and 2.0.0-beta.1.

RECOMMENDATIONS:

  • We recommend you to update prompty to version 2.0.0b2.
  • We recommend you to update @prompty/core to version 2.0.0-beta.2.
  • We recommend you to update Prompty.Core to version 2.0.0-beta.2.

REFERENCES:

The following reports contain further technical details:[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-53598 with a CVSS score of 7.5, exists in prompty loaders due to arbitrary file read via file reference expansion. This flaw allows an attacker-controlled prompt file to use path traversal or an absolute path to cause the host application to read files accessible to the process, potentially disclosing local files available to the application process when expanded values are logged, returned, or otherwise exposed. The vulnerability affects applications that load untrusted.prompty files, user-provided prompt paths, or prompt bundles from less-trusted locations. Affected versions include those prior to 2.0.0b1 and 2.0.0-beta.1.

RECOMMENDATIONS:

  • We recommend you to update prompty to version 2.0.0b2.
  • We recommend you to update @prompty/core to version 2.0.0-beta.2.
  • We recommend you to update Prompty.Core to version 2.0.0-beta.2.

REFERENCES:

The following reports contain further technical details:[emaillocker id="1283"]

[/emaillocker]
crossmenu