CVE-2026-72742: Stanford Nlp Dspy
High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter validation, which triggers encode_image or encode_audio to read and base64-encode any local file path via the os.path.isfile branch in image.py and audio.py, subsequently embedding the file contents into outgoing prompt messages sent to the attacker-controlled model endpoint.
Affected products
- Stanford Nlp Dspy: up to and including 3.3.0b1
Published 2026-08-11. Last modified 2026-09-24.