Langroid
Langroid: vulnerabilidades y CVE
Langroid tiene 11 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses8
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55615 | Crítica (9.2) | 0.46% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no… |
| CVE-2026-54771 | Alta (8.1) | 0.39% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON… |
| CVE-2026-54769 | Crítica (10) | 0.91% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and… |
| CVE-2026-54760 | Crítica (9.3) | 0.65% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text… |
| CVE-2026-50181 | Alta (7.1) | 0.18% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory… |
| CVE-2026-50180 | Alta (8.7) | 0.69% | — | 10 jul 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS`… |
| CVE-2026-25879 | Crítica (9.8) | 0.69% | — | 1 jun 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a… |
| CVE-2026-25481 | Crítica (9.4) | 0.73% | — | 4 feb 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to evaluate the… |
| CVE-2025-46725 | Alta (8.1) | 0.53% | — | 20 may 2025 | Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, an attacker may be… |
| CVE-2025-46724 | Crítica (9.8) | 0.83% | — | 20 may 2025 | Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user input, like the case of a public-facing… |
| CVE-2025-46726 | Alta (7.8) | 0.62% | — | 5 may 2025 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS… |