Vulnerability Description
DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter validation, which triggers encode_image or encode_audio to read and base64-encode any local file path via the os.path.isfile branch in image.py and audio.py, subsequently embedding the file contents into outgoing prompt messages sent to the attacker-controlled model endpoint.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/stanfordnlp/dspy
- https://github.com/stanfordnlp/dspy/commit/c69136b29aca4c00ca6da7667f7b807831889
- https://github.com/stanfordnlp/dspy/issues/10067
- https://www.vulncheck.com/advisories/dspy-0b1-local-file-read-via-image-audio-ou
FAQ
What is CVE-2026-72742?
CVE-2026-72742 is a vulnerability with a CVSS score of 8.6 (HIGH). DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by i...
How severe is CVE-2026-72742?
CVE-2026-72742 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-72742?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.