Langroid是Langroid组织开源的一个利用多代理编程开发LLM的工具。 langroid 0.65.5之前版本存在输入验证错误漏洞,该漏洞源于Neo4jChatAgent将LLM生成的Cypher查询直接传递给Neo4j驱动程序而未经过验证、未设定语句类型白名单且无退出机制,攻击者通过提示注入(直接用户输入或通过RAG读取的间接内容)影响查询文本,可读取或销毁所有图形数据,并在服务器上启用APOC或dbms.security过程时获得操作系统命令和文件系统访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54769 | 10.0 CRITICAL | Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in Ta |
| CVE-2026-54771 | 8.1 HIGH | Langroid: handle_message() executes user-supplied tool JSON without sender verification |
| CVE-2026-50181 | 7.1 HIGH | Langroid: Path traversal in the file tools allows read/write outside configured current di |
| CVE-2026-54760 | Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema- | |
| CVE-2026-50180 | Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbit |
No comments yet