漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Vulnerability Description
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influence the prompt can read or destroy all graph data and, when APOC or dbms.security procedures are enabled on the server, achieve OS-command and filesystem access. This is the same defect class and threat model as the SQLChatAgent prompt-to-SQL-to-RCE issue fixed in version 0.63.0 (CVE-2026-25879); that fix did not extend to the neo4j module. Version 0.65.5 contains a fix for the neo4j module.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Vulnerability Title
langroid 输入验证错误漏洞
Vulnerability Description
Langroid是Langroid组织开源的一个利用多代理编程开发LLM的工具。 langroid 0.65.5之前版本存在输入验证错误漏洞,该漏洞源于Neo4jChatAgent将LLM生成的Cypher查询直接传递给Neo4j驱动程序而未经过验证、未设定语句类型白名单且无退出机制,攻击者通过提示注入(直接用户输入或通过RAG读取的间接内容)影响查询文本,可读取或销毁所有图形数据,并在服务器上启用APOC或dbms.security过程时获得操作系统命令和文件系统访问权限。
CVSS Information
N/A
Vulnerability Type
N/A