Vulnerability DatabaseGHSA-w28w-gp39-m4p6

GHSA-w28w-gp39-m4p6
JavaScript vulnerability analysis and mitigation

Summary

The TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.

Affected packages

  • npm @prompty/core versions <= 0.1.4
  • npm @prompty/core versions <= 2.0.0-beta.4

Impact

Applications that render untrusted, community-supplied, cloned, or LLM-generated .prompty files with the TypeScript runtime could allow attacker-controlled code execution with the privileges of the Node.js host process.

Remediation

Upgrade to @prompty/core 2.0.0-beta.5 or later. The patched renderer sanitizes render inputs to own-data-only values, rejects constructor/prototype member traversal, and disallows template function calls. Ordinary interpolation, conditionals, loops, and own nested data properties remain supported.

Fix details

The fix is merged in PR #404 and includes regression coverage for default Nunjucks rendering, explicit renderer usage, unsafe member lookups, and attempted template function calls.


SourceNVD

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w28w-gp39-m4p6CRITICAL10
  • JavaScript logoJavaScript
  • @prompty/core
NoYesJul 24, 2026
GHSA-pm4m-ph32-ghv5HIGH7.5
  • JavaScript logoJavaScript
  • js-yaml
NoYesJul 24, 2026
GHSA-r28c-9q8g-f849HIGH7.5
  • JavaScript logoJavaScript
  • postcss
NoYesJul 24, 2026
GHSA-r292-9mhp-454mMEDIUM5.3
  • JavaScript logoJavaScript
  • tar
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • github.com/aws/aws-cdk-go/awscdk/v2
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management