Security Flaw in Prompty Markdown Format for LLM Prompts by Microsoft
CVE-2026-73299
10CRITICAL
What is CVE-2026-73299?
The Prompty markdown file format prior to version 0.1.5 and 2.0.0-beta.5 contains a code execution vulnerability due to the TypeScript Nunjucks renderer processing untrusted .prompty template bodies. This flaw allows an attacker to traverse object properties, potentially executing arbitrary JavaScript in the Node.js host process. Versions 0.1.5 and 2.0.0-beta.5 have been patched to address this security issue, ensuring that template evaluation is performed in a more secure manner, restricting unauthorized access.
Affected Version(s)
prompty < 0.1.5 < 0.1.5
prompty >= 2.0.0-alpha.1, < 2.0.0-beta.5 < 2.0.0-alpha.1, 2.0.0-beta.5