CVE-2025-6518

MEDIUM

PySpur-Dev <0.1.18 - Improper Neutralization

Title source: llm
STIX 2.1

Description

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation of the argument user_message leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1336 CWE-791
Status published
Products (20)
pypi/pyspur 0PyPI
PySpur-Dev/pyspur 0.1.0
PySpur-Dev/pyspur 0.1.1
PySpur-Dev/pyspur 0.1.10
PySpur-Dev/pyspur 0.1.11
PySpur-Dev/pyspur 0.1.12
PySpur-Dev/pyspur 0.1.13
PySpur-Dev/pyspur 0.1.14
PySpur-Dev/pyspur 0.1.15
PySpur-Dev/pyspur 0.1.16
... and 10 more
Published Jun 23, 2025
Tracked Since Feb 18, 2026