10 of 10 CVSS: The Prompty vulnerability allowed arbitrary code to be executed in Node.js through .prompty files

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
867
Deposit
0$
The critical vulnerability was found in Prompty, an open Microsoft project to develop applications based on large language models. The error allowed the specially prepared .prompty file to go beyond the usual template processing and run arbitrary JavaScript code with the rights of the Node.js process. The vulnerability received a maximum score of 10 out of 10 on the CVSS scale.

The problem was discovered by the specialists of the AppSec Research Positive Technologies team when testing the developed tool based on artificial intelligence to find vulnerabilities. The deficiency was registered as CVE-2026-73299. The vulnerability affected the TypeScript package @prompty/core versions up to 0.1.4 inclusive, as well as the branch up to 2.0.0-beta.4 inclusive. Microsoft closed the gap in 0.1.5 and 2.0.0-beta.5.

Prompty combines .prompty file format and tools for creating, testing and running industrial implications in generative AI-based applications. The file consists of the YAML configuration and the body of the propt in Markdown, and may also contain model parameters, input data, tools, and template designs. The developer is able to use a single file in different environments and connect different LLM providers.

The vulnerability belongs to the SSTI class, or Server-Side Template Injection. When processing .prompty files, the Nunjucks templater did not limit access to JavaScript objects. A specially formed template allowed you to turn to the properties of constructor and prototype, go beyond the provided logic and achieve JavaScript execution inside the Node.js process.


The consequences of exploitation depended on the rights of the process in which the application worked. With sufficient privileges, the attacker could potentially access the data and secrets of the application, change files and settings, interfere with the operation of the services or violate their availability. The ability to execute arbitrary code with the rights of the application has caused maximum hazard assessment.

The usual text query for the language model for the operation of CVE-2026-73299 is not enough. The attack requires the application to use a vulnerable version of @prompty/core, process the .prompty file through Nunjucks, and get a specially prepared template. The Microsoft description separately specifies the incredulous, community-received, LLM-generated .prompty files.

Increased risk occurs in systems that download such files from external repositories, accept from third-party developers or create automatically using language models. A file with a prop in such scenarios can no longer be considered exclusively a text instruction for LLM, since the template logic is processed by the software component.

To fix the problem, Microsoft changed the Nunjacks render. The corrected implementation allows access only to the own data of the transferred objects, blocks the transition through the constructor and prototype, prohibits the call of functions from templates and clears the input data before processing. Substitution of variables, conditions, loops and access to the usual user data continue to work.

The defense was transferred to the old branch @prompty/core. A separate correction added similar restrictions and tests against SSTI, after which version 0.1.5 appeared.

The vulnerability shows how the development of tools for generative AI is changing the threat model for developers. An prompt file can include configuration, template expressions, and other elements that affect the operation of the application, so getting similar files from external sources creates the risks specific to the software supply chain.

Users of vulnerable versions of @prompty/core need to upgrade to at least version 0.1.5 in the old branch or 2.0.0-beta.5 in the new one.
 
Top Bottom