HIGHPyPI

Prompty: Arbitrary file read via file reference expansion

Prompty: Arbitrary file read via file reference expansion

CVE-2026-53598Published 2 weeks agoUpdated 5 days agoSource: OSV

Affected packages

  • @prompty/core
  • Prompty.Corebefore 2.0.0-beta.2
  • promptybefore 2.0.0b2

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
1.06%
EPSS percentile
61.2%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 61%.

Prompty: Arbitrary file read via file reference expansion | HackTribune