neuron-core/neuron-ai Security Advisories for 1.2.4 (2)
-
[CRITICAL] Neuron MySQLWriteTool allows arbitrary/destructive SQL when exposed to untrusted prompts (agent “footgun”)
PKSA-v9n6-t7d1-c4nb CVE-2025-67510 GHSA-898v-775g-777c
Affected version: <=2.8.11
Reported by:
GitHub -
[HIGH] Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
PKSA-3v4g-ypy5-yqkt CVE-2025-67509 GHSA-j8g6-5gqc-mq36
Affected version: <=2.8.11
Reported by:
GitHub