PT-2025-35805 · Pypi · Smolagents

Nnfrog

·

Publicado

2025-09-03

·

Atualizado

2026-05-24

·

CVE-2025-9959

CVSS v3.1

7.6

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions smolagents (affected versions not specified)
Description Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox enforced by the software. The attack requires a Prompt Injection to trick the agent into creating malicious code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-9959

Produtos afetados

Smolagents