dspy
DSPy
Activity
- Latest release
- 2d ago
- Total releases
- 109
- Cadence
- ~6 days
- Last 12 months
- 12
Details
- License
- custom
- First release
- Apr 14, 2024
| Version | Released | |
|---|---|---|
3.4.0b1
pre
|
3.4.0b1
pre
Dependencies (33)
+ 25 more |
|
3.3.1
patch
|
3.3.1
patch
Dependencies (33)
+ 25 more |
|
3.3.0
minor
|
3.3.0
minor
Dependencies (31)
+ 23 more |
|
3.3.0b1
pre
|
3.3.0b1
pre
Dependencies (30)
+ 22 more |
|
3.2.1
patch
|
3.2.1
patch
Dependencies (33)
+ 25 more |
|
3.2.0
minor
|
3.2.0
minor
Dependencies (33)
+ 25 more |
|
3.1.3
patch
|
3.1.3
patch
Dependencies (32)
+ 24 more |
|
3.1.2
patch
|
3.1.2
patch
Dependencies (32)
+ 24 more |
|
3.1.0
minor
|
3.1.0
minor
Dependencies (32)
+ 24 more |
|
3.1.0b1
pre
|
3.1.0b1
pre
Dependencies (32)
+ 24 more |
|
3.0.4
patch
|
3.0.4
patch
Dependencies (36)
+ 28 more |
|
3.0.4b2
pre
|
3.0.4b2
pre
Dependencies (36)
+ 28 more |
|
3.0.4b1
pre
|
3.0.4b1
pre
Dependencies (36)
+ 28 more |
|
3.0.3
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.3
patch
Dependencies (36)
+ 28 more |
|
3.0.2
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (36)
+ 28 more |
|
3.0.1
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (36)
+ 28 more |
|
3.0.0
major
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (36)
+ 28 more |
|
3.0.0b4
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.0b4
pre
Dependencies (35)
+ 27 more |
|
3.0.0b3
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.0b3
pre
Dependencies (34)
+ 26 more |
|
3.0.0b2
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.0b2
pre
Dependencies (34)
+ 26 more |
|
3.0.0b1
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
3.0.0b1
pre
Dependencies (35)
+ 27 more |
|
2.6.27
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.27
patch
Dependencies (35)
+ 27 more |
|
2.6.27a1
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.27a1
pre
Dependencies (35)
+ 27 more |
|
2.6.26
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.26
patch
Dependencies (35)
+ 27 more |
|
2.6.25
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.25
patch
Dependencies (35)
+ 27 more |
|
2.6.24
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.24
patch
Dependencies (34)
+ 26 more |
|
2.6.23
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.23
patch
Dependencies (34)
+ 26 more |
|
2.6.22
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.22
patch
Dependencies (34)
+ 26 more |
|
2.6.21
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.21
patch
Dependencies (34)
+ 26 more |
|
2.6.20
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.20
patch
Dependencies (34)
+ 26 more |
|
2.6.19
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.19
patch
Dependencies (32)
+ 24 more |
|
2.6.18
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.18
patch
Dependencies (45)
+ 37 more |
|
2.6.17
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.17
patch
Dependencies (45)
+ 37 more |
|
2.6.16
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.16
patch
Dependencies (45)
+ 37 more |
|
2.6.15
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.15
patch
Dependencies (45)
+ 37 more |
|
2.6.14
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.14
patch
Dependencies (45)
+ 37 more |
|
2.6.13
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.13
patch
Dependencies (43)
+ 35 more |
|
2.6.12
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.12
patch
Dependencies (43)
+ 35 more |
|
2.6.11
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.11
patch
Dependencies (44)
+ 36 more |
|
2.6.10
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.10
patch
Dependencies (44)
+ 36 more |
|
2.6.9
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.9
patch
Dependencies (44)
+ 36 more |
|
2.6.9rc1
pre
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.9rc1
pre
Dependencies (44)
+ 36 more |
|
2.6.8
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.8
patch
Dependencies (44)
+ 36 more |
|
2.6.7
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.7
patch
Dependencies (44)
+ 36 more |
|
2.6.6
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.6
patch
Dependencies (44)
+ 36 more |
|
2.6.5
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.5
patch
Dependencies (43)
+ 35 more |
|
2.6.4
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.4
patch
Dependencies (43)
+ 35 more |
|
2.6.3
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.3
patch
Dependencies (43)
+ 35 more |
|
2.6.2
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.2
patch
Dependencies (43)
+ 35 more |
|
2.6.1
patch
1 CVE
CVE-2025-12695
PYSEC-2026-1318
GHSA-vvw2-h478-xwr3
Jul 07, 2026
DSPy does not properly restrict file reads
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class. Affected versions
0.0.1
0.0.2
0.0.3
0.1.3
0.1.4
0.1.5
2.5.1
2.5.10
2.5.11
2.5.12
2.5.13
2.5.14
+ 84 more Show less
2.5.15
2.5.16
2.5.17
2.5.18
2.5.19
2.5.2
2.5.20
2.5.21
2.5.22
2.5.23
2.5.24
2.5.25
2.5.26
2.5.27
2.5.28
2.5.29
2.5.3
2.5.30
2.5.31
2.5.32
2.5.33
2.5.34
2.5.35
2.5.36
2.5.37
2.5.38
2.5.39
2.5.4
2.5.40
2.5.41
2.5.42
2.5.43
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0
2.6.0rc1
2.6.0rc11
2.6.0rc2
2.6.0rc3
2.6.0rc4
2.6.0rc5
2.6.0rc6
2.6.0rc7
2.6.0rc8
2.6.1
2.6.10
2.6.11
2.6.12
2.6.13
2.6.14
2.6.15
2.6.16
2.6.17
2.6.18
2.6.19
2.6.2
2.6.20
2.6.21
2.6.22
2.6.23
2.6.24
2.6.25
2.6.26
2.6.27
2.6.27a1
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.9rc1
3.0.0
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.1
3.0.2
3.0.3
References Updated Jul 07, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (43)
+ 35 more |