Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action

Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action

First seen 13 Aug 2026, 07:41 UTC Feedlycve.akaoma.comwww.thehackerwire.comvuldb.com 91% similarity 84.3

Article Content

Browse articles
ThreatCluster

CVE-2026-73299 is a critical remote code execution vulnerability in the TypeScript Nunjucks renderer of Prompty, affecting versions prior to 0.1.5 and 2.0.0-beta.5. An unauthenticated attacker can exploit this flaw by uploading a malicious .prompty template file, allowing them to execute arbitrary JavaScript in the Node.js process. The vulnerability has been assigned a CVSS base score of 10, indicating its critical nature. Currently, there is no evidence of public proof-of-concept or active exploitation. Users are advised to upgrade to the patched versions and restrict access to .prompty file uploads. The vulnerability was published on 2026-08-12, with immediate intervention recommended due to its severe implications.

Key Points: • CVE-2026-73299 allows remote code execution via malicious .prompty templates. • Versions affected include Prompty prior to 0.1.5 and 2.0.0-beta.5. • Immediate upgrade and access restrictions are recommended to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
CVE-2026-73299 published
CVE-2026-73299 was officially published, detailing a critical RCE vulnerability in Prompty.
Feedly
2026-08-13
Security advisory issued
Advisories recommend upgrading to versions 0.1.5 or 2.0.0-beta.5 to mitigate the vulnerability.
cve.akaoma.com

Community

Browse all →

Tracked Entities in This Story