CVE-2025-9959Disclosure

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Incomplete validation of dunder attributes allows an attacker to escape from the Local Python execution environment sandbox, enforced by smolagents. The attack requires a Prompt Injection in order to trick the agent to create malicious code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-24: 1Mentions · 2026-09-27: 1Technical Details · 2026-05-24: 1Technical Details · 2026-09-27: 105-2409-27
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - smolagents Sandbox Escape via Dunder Attribute Validation Bypass (CVE-2025-9959) smolagents Local Python execution sandbox incompletely blocks Python dunder attribute access, letting attacker-controlled generated code reach dangerous objects (e.g., __class__/__globals__/__subclasses__) and break out. Exploitation requires prompt-injection to coerce the agent into emitting malicious Python, leading to code injection and partial environment compromise. 👉Affected: smolagents (versions unknown)

    Post summary

    The tweet discloses a high-severity sandbox escape vulnerability (CVE-2025-9959) in smolagents caused by incomplete dunder attribute validation, enabling code injection via prompt injection, with no mitigation or active exploitation noted.

    0000085
    308 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2025-9959 - High severity supply chain attack in Smolagents. Incomplete dunder attribute validation allows sandbox escape via prompt injection. CVSS 7.6. Review your use immediately. #CVE #infosec #smolagents #CVEAlert #cybersecurity more: https://www.valtersit.com/cve/CVE-2025-9959/

    Post summary

    The post announces CVE‑2025‑9959—a high‑severity supply chain flaw in Smolagents that permits sandbox escape through prompt injection, with a CVSS score of 7.6.

    00000401
    904 followersView on X

Explore more