@prompty/core
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @prompty/corepage 1 of 1
- CVE-2026-53597HIGHCVSS 8.7EG 8.7✓ Fixed in 2.0.0-beta.32026-07-16
Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable …
- CVE-2026-53598HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.0-beta.22026-07-16
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowe…
Check whether @prompty/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @prompty/core CVEs against the assets you own.
Start Free Scan →