PT-2025-50556 · Neuron · Neutron
Published
2025-12-10
·
Updated
2025-12-11
·
CVE-2025-67510
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Neuron versions prior to 2.8.12
Description
The PHP framework Neuron has an issue where the MySQLWriteTool can execute arbitrary SQL queries provided by a caller, utilizing PDO::prepare() and execute() without restrictions. This occurs because the tool is designed to write SQL, but in an AI agent context, it presents a high risk. Prompt injection or indirect prompt manipulation could lead to the execution of destructive database queries, such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements, depending on the database user's permissions. Deployments exposing an agent with the MySQLWriteTool enabled to untrusted input, or running the tool with a database user possessing broad privileges, are susceptible to this issue.
Recommendations
Update to version 2.8.12 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Neutron