CVE-2025-25362
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-25362, https://github.com/explosion/spacy-llm/issues/492, https://github.com/explosion/spacy-llm/pull/491, https://github.com/explosion/spacy-llm/commit/8bde0490cc1e9de9dd2e84480b7b5cd18a94d739, https://github.com/explosion/spacy-llm, https://www.hacktivesecurity.com/blog/2025/04/01/cve-2025-25362-old-vulnerabilities-new-victims-breaking-llm-prompts-with-ssti, https://pypi.org/project/spacy-llm, https://github.com/advisories/GHSA-793v-gxfp-9q9h