{"id":"CVE-2026-73299","summary":"Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer","details":"Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.","aliases":["GHSA-w28w-gp39-m4p6"],"modified":"2026-09-11T03:30:54.816715568Z","published":"2026-08-12T17:31:38.807Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1336","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73299.json"},"references":[{"type":"WEB","url":"https://github.com/microsoft/prompty/tree/typescript/2.0.0-beta.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73299.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/prompty/security/advisories/GHSA-w28w-gp39-m4p6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73299"},{"type":"FIX","url":"https://github.com/microsoft/prompty/commit/e4a0ebf49e3a78d5d7796c8480bf9a4f0c54d19e"},{"type":"FIX","url":"https://github.com/microsoft/prompty/commit/f5c57c94a0990cca79d095c3daab661b4b1fb89f"},{"type":"FIX","url":"https://github.com/microsoft/prompty/pull/404"},{"type":"FIX","url":"https://github.com/microsoft/prompty/pull/405"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/microsoft/prompty","events":[{"introduced":"0"},{"introduced":"30acb714bf68259760916c97b0c8fdaf1c5a75a0"},{"fixed":"8ea0e74222e1e35b51232878b1ae32adecf1ac14"},{"fixed":"d8891f66b93bfa37f0611186258c953e12e87fd3"},{"fixed":"e4a0ebf49e3a78d5d7796c8480bf9a4f0c54d19e"},{"fixed":"f5c57c94a0990cca79d095c3daab661b4b1fb89f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.1.5"},{"introduced":"2.0.0-alpha.1"},{"fixed":"2.0.0-beta.5"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["csharp/2.0.0-beta.3","rust/2.0.0-beta.3","typescript/2.0.0-beta.4","python/2.0.0b3","typescript/2.0.0-beta.3","python/2.0.0b2","typescript/2.0.0-beta.2","rust/2.0.0-beta.2","csharp/2.0.0-beta.2","python/2.0.0b1","typescript/2.0.0-beta.1","rust/2.0.0-beta.1","csharp/2.0.0-beta.1","rust/2.0.0-alpha.12","typescript/2.0.0-alpha.11","rust/2.0.0-alpha.11","python/2.0.0a11","csharp/2.0.0-alpha.11","csharp/2.0.0-alpha.10","rust/2.0.0-alpha.10","typescript/2.0.0-alpha.10","python/2.0.0a10","rust/2.0.0-alpha.9","typescript/2.0.0-alpha.9","python/2.0.0a9","csharp/2.0.0-alpha.9","rust/2.0.0-alpha.8","typescript/2.0.0-alpha.8","python/2.0.0a8","csharp/2.0.0-alpha.8","typescript/2.0.0-alpha.7","csharp/2.0.0-alpha.7","python/2.0.0a7","csharp/2.0.0-alpha.6","typescript/2.0.0-alpha.6","python/2.0.0a6","csharp/2.0.0-alpha.2","csharp/2.0.0-alpha.1","csharp/0.2.3-beta","csharp/0.2.2-beta","csharp/0.2.1-beta","csharp/0.2.0-beta","csharp/0.1.0-beta","python/0.1.50","python/0.1.49","python/0.1.48","csharp/0.0.23-alpha","csharp/0.0.22-alpha","csharp/0.0.21-alpha","csharp/0.0.20-alpha","csharp/0.0.19-alpha","csharp/0.0.18-alpha","csharp/0.0.17-alpha","csharp/0.0.16-alpha","csharp/0.0.15-alpha","python/0.1.47","python/0.1.46","python/0.1.45","python/0.1.44","python/0.1.43","python/0.1.42","python/0.1.41","python/0.1.40","python/0.1.39","python/0.1.38","python/0.1.37","python/0.1.35","python/0.1.36","python/0.1.34","python/0.1.33","python/0.1.32","python/0.1.31","python/0.1.30","python/0.1.29","python/0.1.28","python/0.1.27","python/0.1.25","python/0.1.24","python/0.1.23","python/0.1.22","python/0.1.21","python/0.1.20","python/0.1.19","python/0.1.18","python/0.1.17","python/0.1.16","python/0.1.15","python/0.1.14","python/0.1.13","python/0.1.12","python/0.1.11","python/0.1.10","python/0.1.9","python/0.1.8","python/0.1.7","python/0.1.6","python/0.1.5","python/0.1.4","python/0.1.3","python/0.1.2","python/0.1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73299.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}