Vulnerability library
Security checkJuly 24, 2026

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpm@prompty/core

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process.

Recommendation

Update the @prompty/core package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 2.0.0-alpha.1, <= 2.0.0-beta.4 <= 0.1.4**
  • Patched version(s): **2.0.0-beta.5 0.1.5**

References

Could your website be exposed too?

SmartScanner can check your website for Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 24, 2026