CVE-2026-71492: Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
DirectoryPromptRegistry.set() interpolates the attacker-controllable Prompt.name into a Path expression with no canonicalization. An application that derives the prompt name from request data lets a caller write attacker-controlled bytes outside the configured registry directory.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-71492 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →