CVE-2026-73299Patch

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and prototype properties to execute JavaScript in the host Node.js process. This issue is fixed in versions 0.1.5 and 2.0.0-beta.5.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-08-12); latest day: 3
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01223Mentions · 2026-08-12: 3Mentions · 2026-08-13: 2Mentions · 2026-08-21: 1Mentions · 2026-09-03: 3PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-09-03: 1Exploit Tool / Code · 2026-08-12: 1Exploit Tool / Code · 2026-09-03: 1Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-09-03: 2Technical Details · 2026-08-12: 2Technical Details · 2026-08-13: 1Technical Details · 2026-09-03: 308-1208-1308-2109-03
Signal classification5 categories
Patch
333.3%
General
222.2%
PoC
222.2%
Disclosure
111.1%
Exploit
111.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-123
Disclosure1Exploit1Patch1
2026-08-132
General1PoC1
2026-08-211
General1
2026-09-033
Patch2PoC1
Full discourse9 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: CVE-2026-73299 (CVSS 10.0) is a critical Microsoft Prompty vulnerability that can lead to remote code execution. A malicious .prompty file can escape the Nunjucks template sandbox through unrestricted JavaScript member access, allowing an unauthenticated attacker to execute arbitrary JavaScript in the host Node.js process. ⚠️ Affected versions include @prompty/core < 0.1.5 and 2.0.0-alpha.1 through 2.0.0-beta.4. 🔴 Update to 0.1.5 or 2.0.0-beta.5 or later. 🔗 http://github.com/microsoft/prompty/security/advisories/… #Microsoft #Prompty #CVE #RCE #NodeJS #JavaScript #CyberSecurity #Infosec

    Post summary

    A new Microsoft Prompty vulnerability (CVE‑2026‑73299) enables remote code execution by escaping the Nunjucks sandbox; users should promptly upgrade to 0.1.5 or 2.0.0‑beta.5 and later.

    29045217.2K
    1.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A critical Prompty vulnerability (CVE-2026-73299, CVSS 10) let a crafted .prompty file escape the template engine and run arbitrary JavaScript in Node.js. #Prompty #Microsoft #SSTI #RCE #CVE202673299 https://meterpreter.org/prompty-cve-2026-73299/

    Post summary

    A critical Prompty flaw (CVE‑2026‑73299, CVSS 10) allows crafted .prompty files to escape the template engine and execute arbitrary JavaScript in Node.js, with a PoC link provided.

    030157969
    13.0K followersView on X
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 12, 2026 🔴 CRITICAL: CVE-2026-26035 (fortinet/fortiweb) AAS 14.9 — PoC available 🔴 CRITICAL: CVE-2026-17218 (ibm/i) AAS 12.9 — exploit available 🔴 CRITICAL: CVE-2026-73299 (microsoft/prompty) AAS 12.8 — exploit available 🔴 CRITICAL: CVE-2026-73263 (prowler-cloud/prowler) AAS 12.7 — exploit available 🔴 CRITICAL: CVE-2026-73300 (budibase/budibase) AAS 12.7 — exploit available + 2 more CRITICAL 30 vulnerabilities — CRITICAL: 7, HIGH: 23 Full bulletin: https://aretiq.ai/bulletins/2026-08-12/

    Post summary

    The bulletin announces seven critical CVEs with available PoC/exploit code, without evidence of active exploitation or patch information.

    00094526
    232 followersView on X
  • ThreatWire@ThreatWire_
    Patch

    @AgentXLuke Indeed. CVE-2026-73299 is particularly serious because a malicious .prompty file can escape the template sandbox and execute arbitrary JavaScript within the Node.js process. Organizations using Prompty should prioritize updating to a patched version.

    Post summary

    The post highlights that CVE-2026-73299 permits arbitrary JavaScript execution via a malicious .prompty file, and urges users to apply a patch to mitigate the vulnerability.

    10010267
    1.3K followersView on X
  • Kaitan ID Security@KaitanSecurity
    General

    ⚡ AI and Template Engine Vulnerabilities: The Supply Chain Blind Spot Two template engine flaws this week deserve special attention given the AI toolchain context. CVE-2026-73299 affects Prompty, a markdown-based LLM prompt format, where the…

    Post summary

    The snippet mentions CVE-2026-73299 affecting Prompty but does not provide technical details, proof‑of‑concepts, exploitation data, or patch information.

    1000030
    80 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [CVE] CVE-2026-73299 [HIGH PRIORITY] #Prompty: Server-Side Template Injection to Remote Code Execution in the @prom... 🔗 https://exploitgrid.net/cve/CVE-2026-73299

    Post summary

    The post announces high‑priority CVE‑2026‑73299 as a server‑side template injection that can lead to remote code execution, and provides a reference link to a proof‑of‑concept on ExploitGrid.

    1000027
    30 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Top Vulnerabilities (CVEs) of the day CVE-2024-27253 CVE-2026-67282 CVE-2026-73299 CVE-2026-16860 CVE-2026-19656 ..🧵👇

    Post summary

    The text merely lists several CVE identifiers with no additional details or actionable information.

    1000043
    30 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    🧩 Microsoft Prompty (@prompty/core) has a CVSS 10 SSTI-to-RCE flaw. CVE-2026-73299: the Nunjucks renderer evaluates untrusted .prompty templates with unrestricted JS. Patch to 0.1.5 or 2.0.0-beta.5 now. #cybersecurity #ciso #cto https://secalerts.co/vulnerability/CVE-2026-73299?utm_campaign=x https://t.co/rC5CttHDbJ

    Post summary

    Microsoft Prompty announced a CVE-2026-73299 vulnerability (CVSS 10 SSTI-to-RCE) that allows untrusted templates to execute JavaScript. It has been patched in releases 0.1.5 and 2.0.0-beta.5.

    00000101
    878 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73299 Arbitrary JavaScript Execution in Prompty Renderer via Prototype Pollution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73299

    Post summary

    The entry announces CVE-2026-73299, describing an arbitrary JavaScript execution vulnerability in Prompty Renderer via prototype pollution, with details linked to Vulmon.

    00000117
    4.1K followersView on X

Explore more