Vendor
DSPy version 3.3.0b1 is vulnerable to arbitrary local file exfiltration via path traversal in its Image and Audio field adapters, allowing an attacker to read and transmit sensitive file contents.