Directory Traversal Vulnerability in Banks Software by Masci
CVE-2026-107716
7.3HIGH
What is CVE-2026-107716?
The Banks software, prior to version 2.5.1, exhibits a directory traversal vulnerability within the DirectoryPromptRegistry component. Attackers with the ability to influence the prompt directory can exploit this issue to access files outside the intended registry root. Specifically, methods such as DirectoryPromptRegistry._scan(), DirectoryPromptRegistry.get(), DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() fail to properly handle symbolic links, leading to unauthorized file disclosures or overwrites. This vulnerability underscores the importance of securing user inputs and directory access. Users are encouraged to upgrade to version 2.5.1 or later to mitigate this risk.
Affected Version(s)
banks < 2.5.1
