CVE-2026-44209
Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system. This vulnerability is fixed in 2.4.2.
Schwachstellenklasse
Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system. This vulnerability is fixed in 2.4.2.
Quellen
- https://github.com/masci/banks/pull/74
- https://github.com/masci/banks/security/advisories/GHSA-gphh-9q3h-jgpp
- https://access.redhat.com/security/cve/CVE-2026-44209
- https://bugzilla.redhat.com/show_bug.cgi?id=2481713
- https://github.com/masci/banks/security/advisories/GHSA-gphh-9q3h-jgpp
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44209.json
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.