CVE-2026-107717

medium

Description

Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0.

References

https://github.com/masci/banks/security/advisories/GHSA-hmq2-7hp6-7crh

https://github.com/masci/banks/releases/tag/v2.5.0

https://github.com/masci/banks/pull/78

https://github.com/masci/banks/commit/02172b816fb84f6a824cc09a8aca7416f53c12cb

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95341

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00279