Directory Traversal Vulnerability in Banks by Masci
CVE-2026-71492
6MEDIUM
What is CVE-2026-71492?
The DirectoryPromptRegistry.set() functionality in Banks prior to version 2.4.5 is vulnerable to directory traversal attacks. The vulnerability arises from the interpolation of unvalidated user input (Prompt.name and Prompt.version) into file paths without proper containment validation. This flaw allows attackers to manipulate file paths, achieving unauthorized access to the file system. Relative traversal patterns can facilitate the exposure of sensitive files or directories, while the option to overwrite target files can lead to further exploitation. The issue underscores the importance of input validation and secure coding practices in application development.
Affected Version(s)
banks < 2.4.5
