Langroid是Langroid组织开源的一个利用多代理编程开发LLM的工具。 Langroid 0.65.2之前版本存在代码注入漏洞,该漏洞源于沙箱逃逸问题,允许未经过身份验证的攻击者实现远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-54771 | 8.1 HIGH | Langroid: handle_message() executes user-supplied tool JSON without sender verification |
| CVE-2026-50181 | 7.1 HIGH | Langroid: Path traversal in the file tools allows read/write outside configured current di |
| CVE-2026-55615 | Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cyphe | |
| CVE-2026-54760 | Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema- | |
| CVE-2026-50180 | Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbit |
No comments yet