← Back

CVE-2025-12695

nvd nist
Published: Nov 4, 2025Modified: Nov 4, 2025

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: reefs@jfrog.com (Secondary)

Description

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

Timeline

No history available yet.