
🚨High - smolagents Sandbox Escape via Dunder Attribute Validation Bypass (CVE-2025-9959) smolagents Local Python execution sandbox incompletely blocks Python dunder attribute access, letting attacker-controlled generated code reach dangerous objects (e.g., __class__/__globals__/__subclasses__) and break out. Exploitation requires prompt-injection to coerce the agent into emitting malicious Python, leading to code injection and partial environment compromise. 👉Affected: smolagents (versions unknown)
Post summary
The tweet discloses a high-severity sandbox escape vulnerability (CVE-2025-9959) in smolagents caused by incomplete dunder attribute validation, enabling code injection via prompt injection, with no mitigation or active exploitation noted.

