Security Flaw in Prompty Markdown Format for LLM Prompts by Microsoft
CVE-2026-73299

10CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
12 August 2026

What is CVE-2026-73299?

The Prompty markdown file format prior to version 0.1.5 and 2.0.0-beta.5 contains a code execution vulnerability due to the TypeScript Nunjucks renderer processing untrusted .prompty template bodies. This flaw allows an attacker to traverse object properties, potentially executing arbitrary JavaScript in the Node.js host process. Versions 0.1.5 and 2.0.0-beta.5 have been patched to address this security issue, ensuring that template evaluation is performed in a more secure manner, restricting unauthorized access.

Affected Version(s)

prompty < 0.1.5 < 0.1.5

prompty >= 2.0.0-alpha.1, < 2.0.0-beta.5 < 2.0.0-alpha.1, 2.0.0-beta.5

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.