VDB
Sign up
MEDIUM5.9

PYSEC-2026-1318

DSPy does not properly restrict file reads

Details

The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/dspy
Introduced in: 0

No fixed version published yet for dspy (pip). Pin to a known-safe version or switch to an alternative.

References