CVE-2025-9959

Source
https://cve.org/CVERecord?id=CVE-2025-9959
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9959.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-9959
Published
2025-09-03T16:53:46.304Z
Modified
2026-07-15T01:49:09.344518650Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Sandbox escape in smolagents Local Python execution environment via dunder attributes
Details

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "cna_assigner": "JFROG",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9959.json"
}
References

Affected packages

Git / github.com/huggingface/smolagents

Affected ranges

Type
GIT
Repo
https://github.com/huggingface/smolagents
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.21.0"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v1.*
v1.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9959.json"