criticalCVSS 10Vulnerability

GHSA-w28w-gp39-m4p6

## Summary The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. ## Affected packages - npm `@prompty/core` versions `<= 0.1.4` - npm `@prompty/core` versions `<= 2.0.0-beta.4` ## Impact Applications that render untrusted, community-supplied, cloned, or LLM-generated `.prompty` files with the TypeScript runtime could allow attacker-controlled code execution with the privileges of the Node.js host process. ## Remediation Upgrade to `@prompty/core` `2.0.0-beta.5` or later. The patched renderer sanitizes render inputs to own-data-only values, rejects constructor/prototype member traversal, and disallows template function calls. Ordinary interpolation, conditionals, loops, and own nested data properties remain supported. ## Fix details The fix is merged in PR #404 and includes regression coverage for default Nunjucks rendering, explicit renderer usage, unsafe member lookups, and attempted template function calls.

Properties

ghsa_id
GHSA-w28w-gp39-m4p6
severity
critical
summary
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
cvss_score
10
cve_id
GHSA-w28w-gp39-m4p6
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
is_ghsa_only
true
ghsa_published
2026-07-24T16:23:59Z
source_url
https://github.com/advisories/GHSA-w28w-gp39-m4p6
ghsa_updated
2026-07-24T16:24:00Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/@prompty/core

AFFECTS (1)

[Software]npm/@prompty/core

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements Used in a Template Engine
[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-w28w-gp39-m4p6 (CVSS 10) — Ninja Signal Threat Intelligence | Ninja Signal