Executive brief
Microsoft Prompty is a framework for building applications that work with language models using template files. The Nunjucks template renderer in the TypeScript runtime fails to properly sanitize untrusted template input, allowing attackers to execute arbitrary JavaScript code on the host system with full privileges. Applications that render untrusted .prompty files from community sources, LLM outputs, or user uploads are at immediate risk of complete system compromise.
Technical details
The vulnerability is a server-side template injection (SSTI) in the @prompty/core Nunjucks renderer affecting versions ≤0.1.4 and ≤2.0.0-beta.4. The renderer evaluates untrusted template bodies with unrestricted JavaScript member access, allowing attackers to traverse constructor and prototype properties via template expressions to execute arbitrary code in the Node.js host process. No authentication or user interaction is required; an attacker merely supplies a malicious .prompty file. The attack vector is network-based with low complexity. Patches are available in @prompty/core 0.1.5 and 2.0.0-beta.5, which sanitize inputs to own-data-only values and reject constructor/prototype traversal.
Affected products
- Microsoft Prompty ≤0.1.4, ≤2.0.0-beta.4
Timeline
- 2026-07-24: disclosed
- 2026-07-24: patched: Patched in @prompty/core 0.1.5 and 2.0.0-beta.5