Directory Traversal Vulnerability in Banks Software by Masci
CVE-2026-107716

7.3HIGH

Key Information:

Vendor

Masci

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107716?

The Banks software, prior to version 2.5.1, exhibits a directory traversal vulnerability within the DirectoryPromptRegistry component. Attackers with the ability to influence the prompt directory can exploit this issue to access files outside the intended registry root. Specifically, methods such as DirectoryPromptRegistry._scan(), DirectoryPromptRegistry.get(), DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() fail to properly handle symbolic links, leading to unauthorized file disclosures or overwrites. This vulnerability underscores the importance of securing user inputs and directory access. Users are encouraged to upgrade to version 2.5.1 or later to mitigate this risk.

Affected Version(s)

banks < 2.5.1

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.