---
id: CVE-2025-6518
aliases:
  - GHSA-8gff-cf92-72pv
  - PYSEC-2026-1844
title: >-
  pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode
  function
summary: >-
  pyspur Incomplete Filtering of Special Elements allowed by SingleLLMCallNode
  function
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
vendor: pyspur
product: pyspur
ecosystem: pip
affected:
  - pyspur <= 0.1.18
published: '2025-06-23'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-8gff-cf92-72pv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6518'
  - url: 'https://github.com/PySpur-Dev/pyspur/issues/289'
  - url: 'https://github.com/PySpur-Dev/pyspur'
  - url: 'https://vuldb.com/?ctiid.313638'
  - url: 'https://vuldb.com/?id.313638'
  - url: 'https://vuldb.com/?submit.593612'
tags:
  - osv
  - pip
epss: 0.00388
epssPercentile: 0.30196
ingestedAt: '2026-07-08T18:25:47.485Z'
---

## Overview

A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It has been classified as critical. Affected is the function SingleLLMCallNode of the file backend/pyspur/nodes/llm/single_llm_call.py of the component Jinja2 Template Handler. The manipulation of the argument user_message leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

## Affected packages

- `pyspur <= 0.1.18`

## Remediation

Refer to the advisory for the patched release.
