{"id":"CVE-2025-67510","summary":"MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)","details":"Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.","aliases":["GHSA-898v-775g-777c"],"modified":"2026-08-12T03:51:19.151009694Z","published":"2025-12-10T22:55:21.253Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67510.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-250","CWE-284"]},"references":[{"type":"WEB","url":"https://github.com/neuron-core/neuron-ai/releases/tag/2.8.12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/67xxx/CVE-2025-67510.json"},{"type":"ADVISORY","url":"https://github.com/neuron-core/neuron-ai/security/advisories/GHSA-898v-775g-777c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67510"},{"type":"FIX","url":"https://github.com/neuron-core/neuron-ai/commit/44bab85d92bf162898ee48d0bcef6ba0d29b59c9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/neuron-core/neuron-ai","events":[{"introduced":"0"},{"fixed":"44bab85d92bf162898ee48d0bcef6ba0d29b59c9"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.8.12"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:neuron-ai:neuron:*:*:*:*:*:*:*:*"}}],"versions":["2.8.7","2.8.11","2.8.10","2.8.9","2.8.8","2.8.6","2.8.5","2.8.4","2.8.3","2.8.2","2.8.1","2.8.0","2.7.0","2.6.7","2.6.6","2.6.4","2.6.5","2.6.3","2.6.2","2.6.1","2.6.0","2.5.8","2.5.7","2.5.6","2.5.5","2.5.4","2.4.4","2.4.3","2.4.2","2.4.1","2.4.0","2.3.5","2.3.4","2.3.3","2.3.2","2.3.1","2.2.12","2.2.11","2.2.10","2.2.9","2.2.8","2.2.5","2.2.4","2.2.3","2.2.2","2.2.1","2.2.0","2.1.1","2.1.0","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","1.17.3","1.17.2","1.17.1","1.16.7","1.17.0","1.16.23","1.16.22","1.16.21","1.16.20","1.16.19","1.16.18","1.16.17","1.16.16","1.16.15","1.16.14","1.16.13","1.16.12","1.16.11","1.16.10","1.16.9","1.16.8","1.16.5","1.16.4","1.16.3","1.16.1","1.16.0","1.15.21","1.15.20","1.15.19","1.15.18","1.15.17","1.15.16","1.15.15","1.15.14","1.15.13","1.15.12","1.15.11","1.15.9","1.15.8","1.15.7","1.15.6","1.15.5","1.15.4","1.15.3","1.15.2","1.15.1","1.15.0","1.14.29","1.14.28","1.14.27","1.14.26","1.14.25","1.14.24","1.14.23","1.14.21","1.14.20","1.14.19","1.14.18","1.14.17","1.14.13","1.14.12","1.14.11","1.14.10","1.14.4","1.14.9","1.14.8","1.14.7","1.14.6","1.14.5","1.14.3","1.14.2","1.14.1","1.14.0","1.13.3","1.13.1","1.13.2","1.13.0","1.12.18","1.12.17","1.12.14","1.12.9","1.12.8","1.12.7","1.12.6","1.12.5","1.12.4","1.12.3","1.12.2","1.12.1","1.12.0","1.11.10","1.11.9","1.11.8","1.11.7","1.11.6","1.11.5","1.11.4","1.11.3","1.11.2","1.11.1","1.11.0","1.10.20","1.10.19","1.10.18","1.10.17","1.10.16","1.10.15","1.10.14","1.10.13","1.10.12","1.10.8","1.10.7","1.10.6","1.10.5","1.10.4","1.10.2","1.10.1","1.10.0","1.9.37","1.9.36","1.9.35","1.9.34","1.9.33","1.9.32","1.9.31","1.9.30","1.9.29","1.9.28","1.9.27","1.9.26","1.9.25","1.9.24","1.9.23","1.9.22","1.9.21","1.9.20","1.9.19","1.9.18","1.9.17","1.9.16","1.9.15","1.9.14","1.9.13","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.8.15","1.8.14","1.8.13","1.8.12","1.8.8","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.7.2","1.7.1","1.7.0","1.6.0","1.5.4","1.5.3","1.5.2","1.5.1","1.5.0","1.4.2","1.4.1","1.4.0","1.3.2","1.3.1","1.3.0","1.2.25","1.2.24","1.2.22","1.2.21","1.2.20","1.2.19","1.2.18","1.2.17","1.2.16","1.2.15","1.2.14","1.2.13","1.2.12","1.2.11","1.2.10","1.2.9","1.2.8","1.2.7","1.2.6","1.2.5","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.3","1.1.2","1.1.1","1.1.0","1.0.1","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-67510.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H"}]}