CVE-2026-25879
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coerce execution of dialect-specific primitives such as `COPY ... FROM PROGRAM`, achieving RCE on the database host.
Leer descripción completaMostrar menos
Fixed in v0.63.0 by defaulting SQLChatAgent to a SELECT-only sqlglot-parsed statement allowlist with a dialect-aware dangerous-pattern blocklist; allow_dangerous_operations=True restores the previous unrestricted behavior for trusted deployments.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.69%
- Percentil entre todas las CVEs puntuadas: 51
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access90 % - Impacto principal
T1059Command and Scripting Interpreterexecution85 % - Impacto secundario
T1005Data from Local Systemcollection80 % - Impacto secundario
T1565.001Stored Data Manipulationimpact75 %
SQLChatAgent ejecuta SQL generado por LLM vulnerable a inyección de prompts sin sanitizar (CWE-89, CWE-94); acceso red sin autenticación (AV:N/PR:N) permite RCE en host de BD mediante primitivas de ejecución de código SQL (pg_execute_server_program, xp_cmdshell).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-89, CWE-94
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-25879",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-25879",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-02T15:03:18.990011Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "langroid",
"product": "langroid",
"versions": [
{
"status": "affected",
"version": "< 0.63.0"
}
]
}
]
}
],
"published": "2026-06-01T23:16:21.930",
"references": [
{
"url": "https://github.com/langroid/langroid/security/advisories/GHSA-mxfr-6hcw-j9rq",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/langroid/langroid/security/advisories/GHSA-mxfr-6hcw-j9rq",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-89"
},
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coerce execution of dialect-specific primitives such as `COPY ... FROM PROGRAM`, achieving RCE on the database host. Fixed in v0.63.0 by defaulting SQLChatAgent to a SELECT-only sqlglot-parsed statement allowlist with a dialect-aware dangerous-pattern blocklist; allow_dangerous_operations=True restores the previous unrestricted behavior for trusted deployments."
},
{
"lang": "es",
"value": "Langroid es un framework para construir aplicaciones impulsadas por modelos de lenguaje grandes. Antes de la versión 0.63.0, SQLChatAgent ejecuta SQL producido por un LLM, el cual es influenciable mediante inyección de prompts. Cuando se configura con un rol de base de datos que tiene privilegios que permiten la ejecución de código o el acceso al sistema de archivos (por ejemplo, PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), un atacante que puede moldear la entrada del agente - incluso indirectamente a través de datos devueltos al LLM - puede forzar la ejecución de primitivas específicas del dialecto como 'COPY ... FROM PROGRAM', logrando RCE en el host de la base de datos. Corregido en la v0.63.0 al establecer por defecto SQLChatAgent a una lista de permitidos de sentencias analizadas por sqlglot de solo SELECT con una lista de bloqueados de patrones peligrosos consciente del dialecto; allow_dangerous_operations=True restaura el comportamiento irrestricto anterior para implementaciones de confianza."
}
],
"lastModified": "2026-07-21T19:10:00.107",
"sourceIdentifier": "security-advisories@github.com"
}