{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@prompty/core--2.0.0-alpha.1--2.0.0-beta.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@prompty/core (\u003c= 0.1.4)","@prompty/core (\u003e= 2.0.0-alpha.1, \u003c= 2.0.0-beta.4)"],"_cs_severities":["critical"],"_cs_tags":["server-side-template-injection","remote-code-execution","nodejs","npm","vulnerability"],"_cs_type":"advisory","_cs_vendors":["prompty"],"content_html":"\u003cp\u003eA critical server-side template injection (SSTI) vulnerability, tracked as GHSA-w28w-gp39-m4p6, has been identified in the \u003ccode\u003e@prompty/core\u003c/code\u003e Nunjucks renderer library for Node.js applications. This vulnerability impacts versions \u003ccode\u003e\u0026lt;= 0.1.4\u003c/code\u003e and \u003ccode\u003e2.0.0-alpha.1\u003c/code\u003e up to \u003ccode\u003e\u0026lt;= 2.0.0-beta.4\u003c/code\u003e. The flaw stems from the renderer's evaluation of untrusted \u003ccode\u003e.prompty\u003c/code\u003e template bodies with unrestricted JavaScript member access. Attackers can exploit this by crafting malicious template content that traverses constructor and prototype properties, enabling arbitrary JavaScript code execution within the host Node.js process. This poses a significant risk to applications that process or render untrusted, community-supplied, cloned, or Large Language Model (LLM)-generated \u003ccode\u003e.prompty\u003c/code\u003e files, as it can lead to full remote code execution with the privileges of the underlying Node.js application.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious \u003ccode\u003e.prompty\u003c/code\u003e template body containing Nunjucks SSTI payloads designed to exploit JavaScript member access.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers this malicious template to a vulnerable application using the \u003ccode\u003e@prompty/core\u003c/code\u003e renderer.\u003c/li\u003e\n\u003cli\u003eThe vulnerable application ingests and attempts to render the untrusted \u003ccode\u003e.prompty\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eDuring rendering, the \u003ccode\u003e@prompty/core\u003c/code\u003e Nunjucks renderer evaluates the template body, which includes the attacker's payload.\u003c/li\u003e\n\u003cli\u003eDue to unrestricted JavaScript member access, the payload successfully traverses constructor and prototype properties of JavaScript objects within the Node.js runtime.\u003c/li\u003e\n\u003cli\u003eThis traversal allows the attacker to execute arbitrary JavaScript code within the context of the host Node.js process.\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE) is achieved, giving the attacker control over the server with the application's privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eApplications that utilize the \u003ccode\u003e@prompty/core\u003c/code\u003e library and render untrusted \u003ccode\u003e.prompty\u003c/code\u003e files are at severe risk. A successful exploitation of this critical vulnerability leads to remote code execution (RCE) on the server. Attackers can leverage this access to steal sensitive data, deploy further malware, establish persistence, or completely compromise the affected system. The impact extends to any data managed by the Node.js application and the underlying operating system. The vulnerability's severity is critical due to the direct path from untrusted input to arbitrary code execution, potentially affecting a broad range of applications that integrate with external template sources, such as those involving user-generated content or LLM integrations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of \u003ccode\u003e@prompty/core\u003c/code\u003e to version \u003ccode\u003e2.0.0-beta.5\u003c/code\u003e or later immediately to apply the security patch. The patched renderer sanitizes render inputs, rejects constructor/prototype member traversal, and disallows template function calls, while maintaining support for ordinary interpolation, conditionals, loops, and own nested data properties.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-24T16:30:25Z","date_published":"2026-07-24T16:30:25Z","id":"https://feed.craftedsignal.io/briefs/2026-07-prompty-ssti-rce/","summary":"A critical server-side template injection vulnerability exists in the @prompty/core Nunjucks renderer, affecting versions \u003c= 0.1.4 and \u003e= 2.0.0-alpha.1 up to \u003c= 2.0.0-beta.4. This flaw allows an attacker to execute arbitrary JavaScript code within the host Node.js process by crafting malicious `.prompty` template bodies. The renderer's unrestricted JavaScript member access permits traversal of constructor and prototype properties, leading to remote code execution when rendering untrusted, community-supplied, cloned, or LLM-generated `.prompty` files.","title":"Server-Side Template Injection to Remote Code Execution in @prompty/core Nunjucks Renderer","url":"https://feed.craftedsignal.io/briefs/2026-07-prompty-ssti-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - @Prompty/Core (\u003e= 2.0.0-Alpha.1, \u003c= 2.0.0-Beta.4)","version":"https://jsonfeed.org/version/1.1"}