CVE-2025-25362

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.

Published 2025-03-05. Last modified 2026-06-17.