Skip to content
CVE-2026-73299 - Exploits & Severity

CVE-2026-73299 - Exploits & Severity

Feedly August 13, 2026

The TypeScript Nunjucks renderer in Prompty evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute arbitrary JavaScript in the host Node.js process.

An unauthenticated attacker over the network can execute arbitrary JavaScript code in the Node.js process hosting Prompty by providing a malicious .prompty template file.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Available in versions 0.1.5 and 2.0.0-beta.5

Update Prompty to version 0.1.5 or 2.0.0-beta.5 or later. Restrict access to .prompty file uploads and processing to trusted sources only. Implement input validation and sandboxing for template processing where possible.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

NVD published the first details for CVE-2026-73299

A CVSS base score of 10 has been assigned.

Feedly found the first article mentioning CVE-2026-73299 . See article

Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action

CVE Daily Brief — 2026-08-13

Prompty Nunjucks Template Injection RCE (CVE-2026-73299)

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

MITRE ATT&CK (1)

Tools (1)