GHSA-w28w-gp39-m4p6
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
빠른 조치
GHSA-w28w-gp39-m4p6 — @prompty/core: 아래 명령으로 수정 버전으로 올리세요.
npm install @prompty/core@0.1.5 상세
## Summary The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.
## Affected packages - npm `@prompty/core` versions `<= 0.1.4` - npm `@prompty/core` versions `<= 2.0.0-beta.4`
## Impact Applications that render untrusted, community-supplied, cloned, or LLM-generated `.prompty` files with the TypeScript runtime could allow attacker-controlled code execution with the privileges of the Node.js host process.
## Remediation Upgrade to `@prompty/core` `2.0.0-beta.5` or later. The patched renderer sanitizes render inputs to own-data-only values, rejects constructor/prototype member traversal, and disallows template function calls. Ordinary interpolation, conditionals, loops, and own nested data properties remain supported.
## Fix details The fix is merged in PR #404 and includes regression coverage for default Nunjucks rendering, explicit renderer usage, unsafe member lookups, and attempted template function calls.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
2.0.0-alpha.1 수정 버전: 2.0.0-beta.5 npm install @prompty/core@2.0.0-beta.5