A high-severity vulnerability tracked as CVE-2026-53597 was disclosed in Microsoft’s Prompty project, where the @prompty/core TypeScript loader could execute attacker-controlled JavaScript embedded in .prompty files. The issue stemmed from use of gray-matter without disabling executable js and javascript frontmatter engines, creating a CWE-94 arbitrary code execution condition during prompt loading. Affected versions span 2.0.0-alpha.1 through versions before 2.0.0-beta.3.
Microsoft addressed the flaw by changing the Prompty TypeScript runtime to explicitly reject executable frontmatter instead of parsing it. The fix, committed in microsoft/prompty@c27402d, adds a rejectExecutableFrontmatter function that throws an error when JavaScript frontmatter is encountered, and includes a test confirming malicious frontmatter cannot execute code or create files. The remediation was released as part of coordinated package updates to 2.0.0-beta.3 across @prompty/core and related packages including @prompty/anthropic, @prompty/openai, and @prompty/foundry.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-53597 was published describing an arbitrary code execution vulnerability in Microsoft's Prompty project caused by executable JavaScript frontmatter handling in the @prompty/core TypeScript loader. The notice states versions from 2.0.0-alpha.1 through before 2.0.0-beta.3 are affected and that 2.0.0-beta.3 contains the fix.
A GitHub commit for Microsoft Prompty changed the TypeScript loader to reject JavaScript frontmatter in .prompty files and added a test to verify malicious frontmatter does not execute. The same change bumped @prompty/core and related packages from 2.0.0-beta.2 to 2.0.0-beta.3, indicating the fix was released in that version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.