Loading
A prompt programming language
Declares an LLM dependency since 2023-06-04 (version 0.0.3).
Advisories that name banks as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-107717GHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messages | Medium | <= 2.4.5 | 2.5.0 | 2026-10-08 |
| CVE-2026-44209GHSA-gphh-9q3h-jgpp: banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI | High | <= 2.4.1 | 2.4.2 | 2026-05-08 |
As declared in PyPI metadata for version 2.5.1. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.