CRITICAL
Stanford NLP
CVE published 2026-08-11
CVE-2026-72742
CVE-2026-72742 is a critical file exfiltration vulnerability in DSPy 3.3.0b1's Image and Audio output field adapters. Attackers with influence over language model outputs can read arbitrary local files by injecting filesystem paths into the url field of parsed Image or Audio typed outputs. This vulnerability allows attackers to exfiltrate sensitive information, potentially leading to unauthorized data bre [truncated]