{"id":"CVE-2025-6518","aliases":["GHSA-8gff-cf92-72pv","PYSEC-2026-1844"],"url":"https://o3.security/vulnerability/CVE-2025-6518","summary":"PySpur-Dev pyspur Jinja2 Template single_llm_call.py SingleLLMCallNode special elements used in a template engine","details":"A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation of the argument user_message leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.","published":"2025-06-23T19:00:11.222Z","modified":"2026-07-15T01:48:54.174905532Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyspur","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6518.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6518"},{"type":"ADVISORY","url":"https://vuldb.com/?id.313638"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.593612"},{"type":"REPORT","url":"https://github.com/PySpur-Dev/pyspur/issues/289"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.313638"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:54.174905532Z"}}