Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-vvw2-h478-xwr3: DSPy does not properly restrict file reads

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

ghsa
#git#intel#perl

Skip to content

Navigation Menu

    • AI CODE CREATION

      • GitHub CopilotWrite better code with AI

      • GitHub SparkBuild and deploy intelligent apps

      • GitHub ModelsManage and compare prompts

      • MCP RegistryNewDiscover and integrate external tools

View all features
  • Pricing

Provide feedback

Saved searches****Use saved searches to filter your results more quickly

Sign up

Appearance settings

  1. GitHub Advisory Database
  2. GitHub Reviewed
  3. CVE-2025-12695

DSPy does not properly restrict file reads

Moderate severity GitHub Reviewed Published Nov 4, 2025 to the GitHub Advisory Database • Updated Nov 4, 2025

Affected versions

<= 3.0.3

Description

Published to the GitHub Advisory Database

Nov 4, 2025

EPSS score

ghsa: Latest News

GHSA-vfpf-xmwh-8m65: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values