{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-11T12:45:12.152","vulnerabilities":[{"cve":{"id":"CVE-2025-67510","sourceIdentifier":"security-advisories@github.com","published":"2025-12-10T23:15:48.983","lastModified":"2026-03-06T19:28:43.897","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","baseScore":9.4,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.5}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-250"},{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:neuron-ai:neuron:*:*:*:*:*:*:*:*","versionEndExcluding":"2.8.12","matchCriteriaId":"D96BDF42-DA23-4C58-B81A-0BC477136145"}]}]}],"references":[{"url":"https://github.com/neuron-core/neuron-ai/commit/44bab85d92bf162898ee48d0bcef6ba0d29b59c9","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/neuron-core/neuron-ai/releases/tag/2.8.12","source":"security-advisories@github.com","tags":["Product","Release Notes"]},{"url":"https://github.com/neuron-core/neuron-ai/security/advisories/GHSA-898v-775g-777c","source":"security-advisories@github.com","tags":["Mitigation","Vendor Advisory"]}]}}]}