PatchSiren

Stanford NLP CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Stanford NLP CVE published 2026-08-11

CVE-2026-72742

CVE-2026-72742 is a critical file exfiltration vulnerability in DSPy 3.3.0b1's Image and Audio output field adapters. Attackers with influence over language model outputs can read arbitrary local files by injecting filesystem paths into the url field of parsed Image or Audio typed outputs. This vulnerability allows attackers to exfiltrate sensitive information, potentially leading to unauthorized data bre [truncated]