DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed output. The JSONAdapter and ChatAdapter parse untrusted language model completions through parse_value into TypeAdapter validation, which triggers encode_image or encode_audio to read and base64-encode any local file path via the os.path.isfile branch in image.py and audio.py, subsequently embedding the file contents into outgoing prompt messages sent to the attacker-controlled model endpoint.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-11 19:18
Updated : 2026-08-12 17:17
NVD link : CVE-2026-72742
Mitre link : CVE-2026-72742
CVE.ORG link : CVE-2026-72742
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
