VYPR
High severityNVD Advisory· Published Jul 16, 2026· Updated Jul 17, 2026

Prompty: Arbitrary File Read via ${file:path} Reference Expansion

CVE-2026-53598

Description

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled prompt file to read local files through absolute paths, .. traversal, or symlink escapes. This issue is fixed in versions 2.0.0-beta.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
promptyPyPI
< 2.0.0b22.0.0b2
@prompty/corenpm
< 2.0.0-beta.22.0.0-beta.2
promptycrates.io
< 2.0.0-beta.22.0.0-beta.2
Prompty.CoreNuGet
< 2.0.0-beta.22.0.0-beta.2

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.