CVE-2025-12695 - Insecure configuration in DSPy lead to arbitrary file read when running untrusted code inside the sandbox
CVE ID : CVE-2025-12695
Published : Nov. 4, 2025, 1:24 p.m. | 1 hour ago
Description : The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Nov. 4, 2025, 1:24 p.m. | 1 hour ago
Description : The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...