PT-2025-44999 · Dspy · Dspy

Published

2025-11-04

·

Updated

2025-11-04

·

CVE-2025-12695

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DSPy (affected versions not specified)
Description An overly permissive sandbox configuration in DSPy can allow attackers to steal sensitive files. This occurs when users create an AI agent that processes user input and utilizes the “PythonInterpreter” class. The issue stems from an insecure configuration that does not adequately restrict access to system resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-12695
GHSA-VVW2-H478-XWR3

Affected Products

Dspy