What is CVE-2026-72742?
CVE-2026-72742: A file exfiltration vulnerability exists in DSPy 3.3.0b1 within the Image and Audio output field adapters. An attacker with influence over language model outputs can read arbitrary local files by injecting a filesystem path into the url field of parsed Image or Audio typed output. Users should update DSPy or temporarily disable these output adapters.
Azərbaycanca: CVE-2026-72742: DSPy 3.3.0b1 versiyasında Image və Audio çıxış adapterlərində fayl sızdırma zəifliyi aşkarlanıb. Zərərli şəxs, dil modelinin çıxışına fayl sistemi yolu inject edərək, url sahəsi vasitəsilə yerli faylları oxuya bilər. DSPy istifadəçiləri proqramı yeniləməli və ya müvəqqəti olaraq bu adapterlərdən istifadəni dayandırmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which version of DSPy is affected by CVE-2026-72742?
This vulnerability exists in DSPy version 3.3.0b1.
What can an attacker do by exploiting CVE-2026-72742?
An attacker can read arbitrary local files by injecting a filesystem path into the url field of an Image or Audio typed output.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.