THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x8wg-4xgc-vr54 (medium) — Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

[GHSA] GHSA-x8wg-4xgc-vr54 (medium) — Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

medgithub_advisoriesPublished 2026-09-02

GHSA-x8wg-4xgc-vr54 Severity: medium CVE: CVE-2026-71492

Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root

## Summary

`DirectoryPromptRegistry.set()` interpolates the attacker-controllable `Prompt.name` into a `Path` expression with no canonicalization. An application that derives the prompt name from request data lets a caller write

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x8wg-4xgc-vr54