Impact
Banks builds LLM prompts from a template language. In versions before 2.5.0, the Prompt.chat_messages() method parses every line of the rendered output as a JSON ChatMessage. If an attacker supplies untrusted data that is rendered into the prompt, the attacker can craft JSON that is interpreted as a system, assistant, or tool message because the ChatMessage.role field accepts any string. This allows the attacker to override application instructions, alter the prompt structure, or confuse downstream tool handling, effectively manipulating the behavior of the LLM. The flaw is a classic input validation issue (CWE‑20) that can lead to privilege escalation within the AI workflow.
Affected Systems
Banks (masci) versions earlier than 2.5.0 are affected. The vulnerability exists in all environments where the application renders untrusted data into prompts that are then passed to an LLM provider.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity. Exploitation requires the attacker to influence the data rendered into the prompt, which is often possible if the application accepts user input or external data. The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is through untrusted input supplied to the Prompt.chat_messages() function, where the attacker can inject arbitrary JSON to create privileged messages.
OpenCVE Enrichment
Github GHSA