Vulnerabilities/

Prompty: Arbitrary file read via file reference expansion

Severity:
High

Description

Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that the resolved path stayed within an authorized directory. An attacker-controlled prompt file could use path traversal or an absolute path to cause the host application to read files accessible to the process.

Recommendation

Update the @prompty/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@prompty/core
Anything's wrong? Let us know Last updated on August 03, 2026