CVE-2025-6518 Overview
CVE-2025-6518 affects PySpur-Dev pyspur through version 0.1.18. The vulnerability resides in the SingleLLMCallNode function inside backend/pyspur/nodes/llm/single_llm_call.py, which processes user-controlled input through a Jinja2 template handler. An authenticated remote attacker can supply a crafted user_message argument that is not properly neutralized before template evaluation. This results in server-side template injection [CWE-791: Incomplete Filtering of Special Elements]. The exploit has been publicly disclosed. While the CVSS 4.0 base score is low, template injection in an LLM orchestration framework can expose sensitive backend context depending on deployment.
Critical Impact
Remote authenticated attackers can inject Jinja2 template syntax into user_message, causing improper neutralization of template directives during LLM prompt construction.
Affected Products
- PySpur-Dev pyspur versions up to and including 0.1.18
- Component: Jinja2 Template Handler within backend/pyspur/nodes/llm/single_llm_call.py
- Function: SingleLLMCallNode
Discovery Timeline
- 2025-06-23 - CVE-2025-6518 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-6518
Vulnerability Analysis
Pyspur is an LLM workflow orchestration framework. The SingleLLMCallNode function constructs prompts by rendering user-supplied input through the Jinja2 template engine. Because the user_message argument is passed into the template renderer without sanitization, an attacker can embed Jinja2 expressions that the engine evaluates on the server. This is a classic server-side template injection pattern classified under [CWE-791]. Successful exploitation depends on the Jinja2 sandbox configuration and the objects exposed within the rendering context. In permissive configurations, template injection can escalate to arbitrary Python execution or disclosure of environment variables and API keys used by the LLM node.
Root Cause
The root cause is direct interpolation of untrusted input into a Jinja2 template without escaping or use of a restricted sandbox environment. User-controllable fields intended as prompt content are treated as trusted template source. Any {{ ... }} or {% ... %} delimiters supplied by the caller are parsed and executed by the template engine.
Attack Vector
The attack is delivered over the network by an authenticated user who submits a workflow or API request containing template metacharacters in the user_message field. No user interaction is required. The vulnerability is exploitable remotely against any pyspur instance up to 0.1.18 that exposes the affected node to callers. Public disclosure references are available in GitHub Issue #289 and the VulDB CTI Report #313638.
No verified proof-of-concept code has been published beyond the referenced advisories. Refer to the VulDB entry for further technical detail.
Detection Methods for CVE-2025-6518
Indicators of Compromise
- Requests to pyspur workflow endpoints containing Jinja2 delimiters such as {{, }}, {%, or %} inside user_message payloads.
- Unexpected outbound network connections or filesystem access originating from the pyspur backend process during LLM node execution.
- Log entries showing Jinja2 rendering errors, UndefinedError, or TemplateSyntaxError correlated with user-submitted prompts.
Detection Strategies
- Inspect API and workflow submission logs for template metacharacters in fields destined for SingleLLMCallNode.
- Monitor the pyspur backend for spawned child processes, unusual file reads under /etc, or reads of environment variables during prompt evaluation.
- Deploy application-layer filters that flag payloads containing __class__, __mro__, __subclasses__, or config.items() patterns commonly used in Jinja2 SSTI exploitation.
Monitoring Recommendations
- Enable verbose logging on the pyspur nodes/llm module and forward events to a centralized SIEM.
- Baseline normal outbound traffic from LLM worker processes and alert on deviations.
- Track authenticated user activity on workflow endpoints and flag anomalous prompt sizes or structure.
How to Mitigate CVE-2025-6518
Immediate Actions Required
- Restrict access to pyspur to trusted, authenticated users only, and place the service behind an authenticating reverse proxy.
- Audit existing workflows for use of SingleLLMCallNode and review historical user_message inputs for injection attempts.
- Sanitize or reject any user_message content containing Jinja2 delimiters before it reaches the template renderer.
Patch Information
No fixed version is listed in the referenced advisories at the time of publication. Monitor the PySpur-Dev pyspur repository for a patched release beyond 0.1.18 and upgrade as soon as a fix is available.
Workarounds
- Replace direct Jinja2 rendering of user input with a SandboxedEnvironment and strip template metacharacters from prompt fields.
- Isolate the pyspur backend in a container with minimal filesystem, network, and credential exposure to limit blast radius if template injection succeeds.
- Remove or disable the SingleLLMCallNode in deployments where it is not required until an upstream fix is released.
# Example: block Jinja2 delimiters at an ingress WAF (illustrative)
# Reject payloads that contain '{{' or '{%' in user_message fields
location /api/workflow {
if ($request_body ~* "(\{\{|\{%)") {
return 403;
}
proxy_pass http://pyspur_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.