External Control of File Name or Path Affecting dspy package, versions [, 3.3.0)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.37% (31st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-DSPY-18751972
  • published13 Aug 2026
  • disclosed12 Aug 2026
  • creditGeorge Chen

Introduced: 12 Aug 2026

NewCVE-2026-72742  (opens in a new tab)
CWE-73  (opens in a new tab)

How to fix?

Upgrade dspy to version 3.3.0 or higher.

Overview

dspy is a DSPy

Affected versions of this package are vulnerable to External Control of File Name or Path via the parsing of untrusted output fields in the Image and Audio adapters. An attacker can access arbitrary local files by injecting a filesystem path into the url field, causing the application to read and encode the file contents, which are then sent to an attacker-controlled endpoint.

CVSS Base Scores

version 4.0
version 3.1