Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107717— Banks: User-controlled prompt input can be parsed as privileged chat messages

Quick assessment

Affected
masci banks
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Banks 使用一个简单的模板语言生成具有实际意义的 LLM 提示词。在版本 2.5.0 之前,Banks 的 Prompt.chat_messages() 方法会尝试将渲染后的模板输出中的每一行解析为 ChatMessage JSON 对象。当应用程序渲染不可信数据,并将返回的 ChatMessage 对象传递给大语言模型(LLM)提供商时,攻击者控制的 JSON 数据可能突破提示词边界,伪装成系统消息、助手消息或工具消息,因为 ChatMessage.role 字段接受任意字符串。这可能导致覆盖应用预设的系统指

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1505 · Server Software Component
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107717

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Banks: User-controlled prompt input can be parsed as privileged chat messages
Source: CVE Program / CVE List V5
Vulnerability Description
Banks generates meaningful LLM prompts using a simple template language. Prior to 2.5.0, Banks Prompt.chat_messages() attempts to parse every line of rendered template output as ChatMessage JSON. When an application renders untrusted data and passes the returned ChatMessage objects to an LLM provider, attacker-controlled JSON can cross the prompt boundary and become a system, assistant, or tool message because ChatMessage.role accepts arbitrary strings. This can override application instructions, alter the intended prompt structure, or confuse downstream tool and message handling. This issue is fixed in version 2.5.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
masci banks < 2.5.0 -

II. Public POCs for CVE-2026-107717

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107717

请登录查看更多情报信息。

Other References for CVE-2026-107717 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107717

No comments yet


Leave a comment