THREAT OPS › Threat News › [GHSA] GHSA-x8wg-4xgc-vr54 (medium) — Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
[GHSA] GHSA-x8wg-4xgc-vr54 (medium) — Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
GHSA-x8wg-4xgc-vr54 Severity: medium CVE: CVE-2026-71492
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
## Summary
`DirectoryPromptRegistry.set()` interpolates the attacker-controllable `Prompt.name` into a `Path` expression with no canonicalization. An application that derives the prompt name from request data lets a caller write
Indicators of compromise
- CVE-2026-71492cve
Original source: https://github.com/advisories/GHSA-x8wg-4xgc-vr54