PT-2025-35805 · Pypi · Smolagents

Nnfrog

·

Published

2025-09-03

·

Updated

2026-05-24

·

CVE-2025-9959

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions smolagents (affected versions not specified)
Description Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox enforced by the software. The attack requires a Prompt Injection to trick the agent into creating malicious code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-9959

Affected Products

Smolagents