PT-2025-43137 · Hugging Face · Smolagents

Published

2025-09-25

·

Updated

2025-10-30

·

CVE-2025-11844

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Hugging Face Smolagents versions prior to 1.22.0
Description The software contains an XPath injection issue in the search item ctrl f function within the src/smolagents/vision web browser.py file. The function builds an XPath query by combining user-provided input directly into the XPath expression without sufficient sanitization or escaping. This allows an attacker to inject malicious XPath syntax, potentially altering the query's logic. This can lead to bypassing search filters, accessing unintended DOM elements, and disrupting web automation workflows, potentially resulting in information disclosure and compromised AI agent interactions. The API endpoint is not mentioned. The vulnerable parameter is not mentioned.
Recommendations Upgrade to Smolagents version 1.22.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14894
CVE-2025-11844
GHSA-8MF9-RMGW-33QC

Affected Products

Smolagents