CRITICAL9.4Packagist
GHSA-898v-775g-777c· CVE-2025-67510Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Modified: 12/11/2025
package
pkg:packagist/neuron-core/neuron-ai
Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
Modified: 12/11/2025
Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
Modified: 12/11/2025