MediumVulnerabilityLLM-specific
GHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messages
- Identifiers
- CVE-2026-107717GHSA-hmq2-7hp6-7crh
- Published
- Record updated
Summary
Banks' `Prompt.chat_messages()` method parses every rendered output line as a possible `ChatMessage` JSON object. If attacker-controlled template data renders to JSON such as `{"role":"system","content":"..."}`, Banks returns it as a privileged `system` message rather than plain user text. Applications that render untrusted input with this method and pass the results directly to an LLM provider may be exposed to chat role injection and prompt boundary bypass, with practical impact depending on how the application uses Banks.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database
- Medium'AgentCorruption' Puts AWS Environments At Risk With Single PromptSimilar attack · Dark Reading
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database