{"id":"PYSEC-2026-1318","summary":"DSPy does not properly restrict file reads","details":"The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.","aliases":["CVE-2025-12695","GHSA-vvw2-h478-xwr3"],"modified":"2026-07-07T17:46:39.452854250Z","published":"2026-07-07T16:03:09.472439Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12695"},{"type":"PACKAGE","url":"https://github.com/stanfordnlp/dspy"},{"type":"WEB","url":"https://research.jfrog.com/vulnerabilities/dspy-sandbox-escape-arbitrary-file-read-jfsa-2025-001495652"},{"type":"PACKAGE","url":"https://pypi.org/project/dspy"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vvw2-h478-xwr3"}],"affected":[{"package":{"name":"dspy","ecosystem":"PyPI","purl":"pkg:pypi/dspy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.0.3"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.1.3","0.1.4","0.1.5","2.5.1","2.5.10","2.5.11","2.5.12","2.5.13","2.5.14","2.5.15","2.5.16","2.5.17","2.5.18","2.5.19","2.5.2","2.5.20","2.5.21","2.5.22","2.5.23","2.5.24","2.5.25","2.5.26","2.5.27","2.5.28","2.5.29","2.5.3","2.5.30","2.5.31","2.5.32","2.5.33","2.5.34","2.5.35","2.5.36","2.5.37","2.5.38","2.5.39","2.5.4","2.5.40","2.5.41","2.5.42","2.5.43","2.5.5","2.5.6","2.5.7","2.5.8","2.5.9","2.6.0","2.6.0rc1","2.6.0rc11","2.6.0rc2","2.6.0rc3","2.6.0rc4","2.6.0rc5","2.6.0rc6","2.6.0rc7","2.6.0rc8","2.6.1","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.15","2.6.16","2.6.17","2.6.18","2.6.19","2.6.2","2.6.20","2.6.21","2.6.22","2.6.23","2.6.24","2.6.25","2.6.26","2.6.27","2.6.27a1","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.8","2.6.9","2.6.9rc1","3.0.0","3.0.0b1","3.0.0b2","3.0.0b3","3.0.0b4","3.0.1","3.0.2","3.0.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/dspy/PYSEC-2026-1318.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}