Security Advisory

CVE-2025-25362

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-05 00:00:00
Last updated 2025-04-08 20:35:57
Assigner mitre
CVSS score 9.8
State PUBLISHED

Description

A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.