Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hmq2-7hp6-7crh | Banks: User-controlled prompt input can be parsed as privileged chat messages |
Thu, 08 Oct 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Masci
Masci banks |
|
| Vendors & Products |
Masci
Masci banks |
Thu, 08 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0. | |
| Title | Banks: User-controlled prompt input can be parsed as privileged chat messages | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T21:38:07.447Z
Reserved: 2026-10-08T17:21:52.975Z
Link: CVE-2026-107717
No data.
Status : Deferred
Published: 2026-10-08T22:17:27.560
Modified: 2026-10-08T22:17:27.710
Link: CVE-2026-107717
No data.
OpenCVE Enrichment
Updated: 2026-10-08T22:30:18Z
-
CWE-20
Improper Input Validation
Github GHSA