What is CVE-2026-61536?
This vulnerability in Banks, an LLM template tool, occurs due to hazardous `importlib.import_module()` resolution of the `import_path` field from Tool JSON objects within {% completion %} blocks. Systems running versions prior to 2.4.3 are affected, allowing an attacker to load arbitrary Python modules via a crafted JSON payload. Users should immediately upgrade to version 2.4.3.
Azərbaycanca: Banks adlı LLM şablon alətində aşkar edilmiş bu boşluq, {% completion %} blokları daxilindəki Tool JSON obyektlərindən `import_path` sahəsinin təhlükəli şəkildə `importlib.import_module()` ilə çağırılması nəticəsində yaranır. Versiya 2.4.3-dən əvvəlki versiyaları istifadə edən sistemlər təsirlənir, hücumçu xüsusi hazırlanmış JSON vasitəsilə ixtiyari Python modullarını yükləyə bilər. İstifadəçilərə dərhal 2.4.3 versiyasına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions are affected by CVE-2026-61536 in the Banks tool?
All versions prior to 2.4.3 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-61536?
An attacker can load arbitrary Python modules via a crafted JSON payload.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.