CVE-2026-107717 — Banks generates meaningful LLM prompts using a simple template language.
Description
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/masci/banks/commit/02172b816fb84f6a824cc09a8aca7416f53c12cb
- advisory[email protected]https://github.com/masci/banks/pull/78
- advisory[email protected]https://github.com/masci/banks/releases/tag/v2.5.0
- advisory[email protected]https://github.com/masci/banks/security/advisories/GHSA-hmq2-7hp6-7crh
Related threats
same CWE or vendorCVE-2026-107726 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
CVE-2026-107726 · 1h ago
CVE-2026-107720 — fast-jwt provides fast JSON Web Token (JWT) implementation.
CVE-2026-107720 · 1h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 6h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 6h ago
Coraza: ProcessURI silently drops QUERY_STRING and ARGS_GET on URI parse failure — defense-in-depth bypass for non-net/http integrations
OSV · 6h ago
Coraza body processor has a JSON key collision that allows unauthenticated attackers to bypass OWASP CRS inspection
OSV · 6h ago