CVE-2025-65896

CRITICAL

long2ice asyncmy < 0.2.10 - SQL Injection via Crafted Dict Keys

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

Scores

CVSS v3 9.8
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
long2ice/asyncmy < 0.2.10
pypi/asyncmy 0PyPI
Published Dec 02, 2025
Tracked Since Feb 18, 2026