CRITICAL9.8
PYSEC-2026-1934
Spacy-LLM Server-Side Template Injection (SSTI) vulnerability
Quick fix
PYSEC-2026-1934 — spacy-llm: upgrade to the fixed version with the command below.
pip install --upgrade 'spacy-llm>=0.7.3'Details
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-25362[ADVISORY]
- https://github.com/explosion/spacy-llm/issues/492[WEB]
- https://github.com/explosion/spacy-llm/pull/491[WEB]
- https://github.com/explosion/spacy-llm/commit/8bde0490cc1e9de9dd2e84480b7b5cd18a94d739[WEB]
- https://github.com/explosion/spacy-llm[PACKAGE]
- https://www.hacktivesecurity.com/blog/2025/04/01/cve-2025-25362-old-vulnerabilities-new-victims-breaking-llm-prompts-with-ssti[WEB]
- https://pypi.org/project/spacy-llm[PACKAGE]
- https://github.com/advisories/GHSA-793v-gxfp-9q9h[ADVISORY]