Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107716— Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry

Quick assessment

Affected
masci banks
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Banks 使用一种简单的模板语言生成有意义的 LLM 提示词。在 2.5.1 版本之前,Banks 的 未拒绝指向 或已发现及已有的 提示词文件符号链接的访问。如果应用程序中存在不受信任的用户能够影响提示词目录的情况, 和 方法可能会跟随符号链接并访问注册表根目录之外的文件,从而导致信息泄露;同时, 、 和 方法可能会读取或覆盖外部链接目标。该漏洞要求攻击者对注册表目录或其解压后的内容具有一定的影响力。此问题已在 2.5.1 版本中修复。

CVSS 7.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107716

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Source: CVE Program / CVE List V5
Vulnerability Description
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.1, Banks DirectoryPromptRegistry does not reject symbolic links for index.json or discovered and existing .jinja prompt files. In an application where untrusted users can influence a prompt directory, DirectoryPromptRegistry._scan() and DirectoryPromptRegistry.get() can follow a link outside the registry root and disclose a file, while DirectoryPromptRegistry.set(), DirectoryPromptRegistry._save(), and DirectoryPromptRegistry._load() can read or overwrite an external link target. The issue requires attacker influence over the registry directory or its extracted contents. This issue is fixed in version 2.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
masci banks < 2.5.1 -

II. Public POCs for CVE-2026-107716

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107716

请登录查看更多情报信息。

Other References for CVE-2026-107716 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107716

No comments yet


Leave a comment