Impact
Banks generates prompt templates using a simple language. Before version 2.5.1 the DirectoryPromptRegistry class fails to disallow symbolic links that point outside its registry directory for index.json or prompt files. When an attacker can set or influence the registry directory or the files it contains, the methods _scan(), get(), set(), _save(), and _load() can follow those links and either read a file on the host or overwrite an existing one. This results in disclosure or modification of arbitrary files, exposing sensitive data or enabling further compromise. The flaw is a classic path‑traversal vulnerability (CWE‑22/CWE‑59).
Affected Systems
The affected product is the banks application from the masci vendor. All releases older than 2.5.1 are vulnerable; the issue is fixed in 2.5.1 and later.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to influence the registry directory or its extracted contents, implying a local or application‑level attack vector, possibly through user input that specifies directory paths. Once a symbolic link is controlled, file read or overwrite becomes trivial. The high CVSS and the potential for arbitrary file manipulation warrant urgent remediation.
OpenCVE Enrichment
Github GHSA