CVE-2026-71492 | masci banks up to 2.4.4 DirectoryPromptRegistry directory.py DirectoryPromptRegistry.set name/version path traversal
A vulnerability classified as critical was found in masci banks up to 2.4.4. Affected by this vulnerability is the function DirectoryPromptRegistry.set of the file src/banks/registries/directory.py of the component DirectoryPromptRegistry. Executing a manipulation of the argument name/version can lead to path traversal.
This vulnerability appears as CVE-2026-71492. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More