
🚨 CRITICAL: CVE-2026-73299 (CVSS 10.0) is a critical Microsoft Prompty vulnerability that can lead to remote code execution. A malicious .prompty file can escape the Nunjucks template sandbox through unrestricted JavaScript member access, allowing an unauthenticated attacker to execute arbitrary JavaScript in the host Node.js process. ⚠️ Affected versions include @prompty/core < 0.1.5 and 2.0.0-alpha.1 through 2.0.0-beta.4. 🔴 Update to 0.1.5 or 2.0.0-beta.5 or later. 🔗 http://github.com/microsoft/prompty/security/advisories/… #Microsoft #Prompty #CVE #RCE #NodeJS #JavaScript #CyberSecurity #Infosec
Post summary
A new Microsoft Prompty vulnerability (CVE‑2026‑73299) enables remote code execution by escaping the Nunjucks sandbox; users should promptly upgrade to 0.1.5 or 2.0.0‑beta.5 and later.






