{"data":{"id":"3d0c50f4-41f0-438e-b01b-c719387ce622","title":"GHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messages","summary":"Banks' `Prompt.chat_messages()` method parses every rendered output line as a possible `ChatMessage` JSON object. If attacker-controlled template data renders to JSON such as `{\"role\":\"system\",\"content\":\"...\"}`, Banks returns it as a privileged `system` message rather than plain user text. Applications that render untrusted input with this method and pass the results directly to an LLM provider may be exposed to chat role injection and prompt boundary bypass, with practical impact depending on how the application uses Banks.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-hmq2-7hp6-7crh","publishedAt":"2026-10-08T22:10:01.000Z","cveId":"CVE-2026-107717","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["prompt_injection","jailbreak"],"issueType":"vulnerability","affectedPackages":["banks@<= 2.4.5 (fixed: 2.5.0)"],"affectedPackageNames":["banks"],"affectedVendors":[],"affectedVendorsRaw":["Banks"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00279,"epssCheckedAt":"2026-10-10T03:00:40.088Z","kevDateAdded":null,"advisoryAliases":["GHSA-hmq2-7hp6-7crh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T22:10:01.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","safety"],"aiComponentTargeted":"framework","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":null,"atlasIds":["AML.T0051"]}}