{"data":{"id":"7e3ef578-1d4a-4ab9-b610-4c3cb7807216","title":"GHSA-w28w-gp39-m4p6: Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer","summary":"The @prompty/core Nunjucks renderer (a template engine for the Prompty framework) had a critical vulnerability where it could execute arbitrary JavaScript code when processing untrusted template files. An attacker could use special template syntax to access internal JavaScript properties and run malicious code on the server.","solution":"Upgrade @prompty/core to version 2.0.0-beta.5 or later. The patch sanitizes template inputs to only allow own-data values, blocks access to constructor and prototype properties, and prevents template function calls while preserving normal template features like variable substitution, conditionals, and loops.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-w28w-gp39-m4p6","publishedAt":"2026-07-24T16:23:59.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["@prompty/core@>= 2.0.0-alpha.1, <= 2.0.0-beta.4 (fixed: 2.0.0-beta.5)","@prompty/core@<= 0.1.4 (fixed: 0.1.5)"],"affectedVendors":[],"affectedVendorsRaw":["Prompty","@prompty/core"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-07-24T16:23:59.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality","availability"],"aiComponentTargeted":"framework","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}