{"id":"CVE-2026-53598","summary":"Prompty: Arbitrary File Read via ${file:path} Reference Expansion","details":"Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2.","aliases":["GHSA-wxhm-2mq7-7697"],"modified":"2026-07-19T03:31:04.011950951Z","published":"2026-07-16T14:59:01.797Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-200","CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53598.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53598.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/prompty/security/advisories/GHSA-wxhm-2mq7-7697"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53598"},{"type":"FIX","url":"https://github.com/microsoft/prompty/commit/88ac9948d7d37995edbb2f6d36913436626c39e1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/microsoft/prompty","events":[{"introduced":"0"},{"fixed":"88ac9948d7d37995edbb2f6d36913436626c39e1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.0.0-beta.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["python/2.0.0b1","typescript/2.0.0-beta.1","rust/2.0.0-beta.1","csharp/2.0.0-beta.1","rust/2.0.0-alpha.12","typescript/2.0.0-alpha.11","rust/2.0.0-alpha.11","python/2.0.0a11","csharp/2.0.0-alpha.11","csharp/2.0.0-alpha.10","rust/2.0.0-alpha.10","typescript/2.0.0-alpha.10","python/2.0.0a10","rust/2.0.0-alpha.9","typescript/2.0.0-alpha.9","python/2.0.0a9","csharp/2.0.0-alpha.9","rust/2.0.0-alpha.8","typescript/2.0.0-alpha.8","python/2.0.0a8","csharp/2.0.0-alpha.8","typescript/2.0.0-alpha.7","csharp/2.0.0-alpha.7","python/2.0.0a7","csharp/2.0.0-alpha.6","typescript/2.0.0-alpha.6","python/2.0.0a6","csharp/2.0.0-alpha.2","csharp/2.0.0-alpha.1","typescript/2.0.0-alpha.5","python/2.0.0a5","typescript/2.0.0-alpha.4","python/2.0.0a4","vscode/2.0.0-pre.1","typescript/2.0.0-alpha.3","python/2.0.0a3","python/2.0.0a2","@prompty/openai-v2.0.0-alpha.1","@prompty/foundry-v2.0.0-alpha.1","@prompty/core-v2.0.0-alpha.1","@prompty/anthropic-v2.0.0-alpha.1","python/2.0.0a1","csharp/0.2.2-beta","python/1.0.0b3","python/1.0.0b2","python/1.0.0b1","csharp/0.2.1-beta","csharp/0.2.0-beta","csharp/0.1.0-beta","python/0.1.50","python/0.1.49","python/0.1.48","csharp/0.0.23-alpha","csharp/0.0.22-alpha","csharp/0.0.21-alpha","csharp/0.0.20-alpha","csharp/0.0.19-alpha","csharp/0.0.18-alpha","csharp/0.0.17-alpha","csharp/0.0.16-alpha","csharp/0.0.15-alpha","python/0.1.47","python/0.1.46","python/0.1.45","python/0.1.44","python/0.1.43","python/0.1.42","python/0.1.41","python/0.1.40","python/0.1.39","python/0.1.38","python/0.1.37","python/0.1.35","python/0.1.36","python/0.1.34","python/0.1.33","python/0.1.32","python/0.1.31","python/0.1.30","python/0.1.29","python/0.1.28","python/0.1.27","python/0.1.25","python/0.1.24","python/0.1.23","python/0.1.22","python/0.1.21","python/0.1.20","python/0.1.19","python/0.1.18","python/0.1.17","python/0.1.16","python/0.1.15","python/0.1.14","python/0.1.13","python/0.1.12","python/0.1.11","python/0.1.10","python/0.1.9","python/0.1.8","python/0.1.7","python/0.1.6","python/0.1.5","python/0.1.4","python/0.1.3","python/0.1.2","python/0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-53598.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}