CVE-2025-12695

MEDIUM

DSPy - Arbitrary File Read via PythonInterpreter Sandbox Escape

Title source: llm
STIX 2.1

Description

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

References (1)

Core 1

Scores

CVSS v3 5.9
EPSS 0.0001
EPSS Percentile 1.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-653
Status published
Products (1)
pypi/dspy 0PyPI
Published Nov 04, 2025
Tracked Since Feb 18, 2026