Directory Traversal Vulnerability in Banks by Masci
CVE-2026-71492

6MEDIUM

Key Information:

Vendor

Masci

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-71492?

The DirectoryPromptRegistry.set() functionality in Banks prior to version 2.4.5 is vulnerable to directory traversal attacks. The vulnerability arises from the interpolation of unvalidated user input (Prompt.name and Prompt.version) into file paths without proper containment validation. This flaw allows attackers to manipulate file paths, achieving unauthorized access to the file system. Relative traversal patterns can facilitate the exposure of sensitive files or directories, while the option to overwrite target files can lead to further exploitation. The issue underscores the importance of input validation and secure coding practices in application development.

Affected Version(s)

banks < 2.4.5

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.