CVE-2025-12695
MEDIUMDescription
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.
Is your site exposed to CVE-2025-12695?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-12695? +
How severe is CVE-2025-12695? +
How do I check if I'm vulnerable to CVE-2025-12695? +
Related Vulnerabilities
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by …
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write …
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using …
When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using …
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network …
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.