{"id":"CVE-2026-72742","summary":"DSPy 3.3.0b1 Local File Read via Image/Audio Output Field Parsing","details":"DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter validation, which triggers encode_image or encode_audio to read and base64-encode any local file path via the os.path.isfile branch in image.py and audio.py, subsequently embedding the file contents into outgoing prompt messages sent to the attacker-controlled model endpoint.","modified":"2026-08-14T03:51:47.636865773Z","published":"2026-08-11T18:50:47.811Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-73"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72742.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72742.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72742"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dspy-0b1-local-file-read-via-image-audio-output-field-parsing"},{"type":"REPORT","url":"https://github.com/stanfordnlp/dspy/issues/10067"},{"type":"FIX","url":"https://github.com/stanfordnlp/dspy/commit/c69136b29aca4c00ca6da7667f7b80783188980e"},{"type":"PACKAGE","url":"https://github.com/stanfordnlp/dspy"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/stanfordnlp/dspy","events":[{"introduced":"0"},{"fixed":"c69136b29aca4c00ca6da7667f7b80783188980e"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.3.0b1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.3.0b1","3.2.0","3.1.3","3.1.2","3.1.1","3.1.0b1","3.0.4b2","3.0.4b1","3.0.3","3.0.2","3.0.1","3.0.0","3.0.0b4","3.0.0b3","3.0.0b2","3.0.0b1","2.6.26","2.6.27","2.6.27a1","2.6.25","2.6.24","2.6.23","2.6.22","2.6.21","2.6.20","2.6.19","2.6.18","2.6.17","2.6.16","2.6.15","2.6.14","2.6.13","2.6.12","2.6.11","2.6.10","2.6.9","2.6.9rc1","2.6.8","2.6.7","2.6.6","2.6.5","2.6.4","2.6.3","2.6.2","2.6.1","2.6.0","2.6.0rc9","2.6.0rc10","2.6.0rc8","2.6.0rc7","2.6.0rc6","2.6.0rc5","2.6.0rc4","2.6.0rc3","2.6.0rc2","2.6.0rc1","2.5.43","2.5.42","2.5.41","2.5.40","2.5.39","2.5.38","2.5.37","2.5.36","2.5.35","2.5.34","2.5.33","2.5.32","2.5.31","2.5.30","2.5.29","2.5.27","2.5.26","2.5.25","2.5.24","2.5.23","2.5.22","2.5.21","2.5.20","2.5.19","2.5.18","2.5.17","2.5.16","2.5.15","2.5.14","2.5.13","2.5.12","2.5.11","2.5.10","2.5.9","2.5.8","2.5.7","2.5.6","2.5.5","2.5.4","2.5.3","2.5.2","2.5.1","2.5.0","2.4.17","2.4.16","2.4.15","2.4.14","2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72742.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}]}