Description
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.
Published: 2026-10-08
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote File Disclosure/Overwrite
Action: Apply patch
AI Analysis

Impact

Banks generates prompt templates using a simple language. Before version 2.5.1 the DirectoryPromptRegistry class fails to disallow symbolic links that point outside its registry directory for index.json or prompt files. When an attacker can set or influence the registry directory or the files it contains, the methods _scan(), get(), set(), _save(), and _load() can follow those links and either read a file on the host or overwrite an existing one. This results in disclosure or modification of arbitrary files, exposing sensitive data or enabling further compromise. The flaw is a classic path‑traversal vulnerability (CWE‑22/CWE‑59).

Affected Systems

The affected product is the banks application from the masci vendor. All releases older than 2.5.1 are vulnerable; the issue is fixed in 2.5.1 and later.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to influence the registry directory or its extracted contents, implying a local or application‑level attack vector, possibly through user input that specifies directory paths. Once a symbolic link is controlled, file read or overwrite becomes trivial. The high CVSS and the potential for arbitrary file manipulation warrant urgent remediation.

Generated by OpenCVE AI on October 8, 2026 at 22:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the banks application to 2.5.1 or newer.
  • Ensure the registry directory resides in a location not writable or selectable by untrusted users.
  • Verify that no symbolic links are present—or implement validation to reject symlinks—before processing prompt files.

Generated by OpenCVE AI on October 8, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-556j-vv39-8rqv Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
History

Thu, 08 Oct 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Masci
Masci banks
Vendors & Products Masci
Masci banks

Thu, 08 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.
Title Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Weaknesses CWE-22
CWE-59
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T21:33:13.391Z

Reserved: 2026-10-08T17:21:52.975Z

Link: CVE-2026-107716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T22:17:27.323

Modified: 2026-10-08T22:17:27.480

Link: CVE-2026-107716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')