Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-55615— Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Quick assessment

Affected
langroid langroid
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Langroid是Langroid组织开源的一个利用多代理编程开发LLM的工具。 langroid 0.65.5之前版本存在输入验证错误漏洞,该漏洞源于Neo4jChatAgent将LLM生成的Cypher查询直接传递给Neo4j驱动程序而未经过验证、未设定语句类型白名单且无退出机制,攻击者通过提示注入(直接用户输入或通过RAG读取的间接内容)影响查询文本,可读取或销毁所有图形数据,并在服务器上启用APOC或dbms.security过程时获得操作系统命令和文件系统访问权限。

AI Predicted 9.8 Difficulty: Easy EPSS 0.46% · P38

Affected Version Matrix 1

VendorProduct Version RangeStatus
langroid langroid < 0.65.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55615

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Source: CVE Program / CVE List V5
Vulnerability Description
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is influenceable by prompt injection (direct user input or indirect content the agent reads back via RAG), so an attacker who can influence the prompt can read or destroy all graph data and, when APOC or dbms.security procedures are enabled on the server, achieve OS-command and filesystem access. This is the same defect class and threat model as the SQLChatAgent prompt-to-SQL-to-RCE issue fixed in version 0.63.0 (CVE-2026-25879); that fix did not extend to the neo4j module. Version 0.65.5 contains a fix for the neo4j module.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输出中的特殊元素转义处理不恰当(注入)
Source: CVE Program / CVE List V5
Vulnerability Title
langroid 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Langroid是Langroid组织开源的一个利用多代理编程开发LLM的工具。 langroid 0.65.5之前版本存在输入验证错误漏洞,该漏洞源于Neo4jChatAgent将LLM生成的Cypher查询直接传递给Neo4j驱动程序而未经过验证、未设定语句类型白名单且无退出机制,攻击者通过提示注入(直接用户输入或通过RAG读取的间接内容)影响查询文本,可读取或销毁所有图形数据,并在服务器上启用APOC或dbms.security过程时获得操作系统命令和文件系统访问权限。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
langroid langroid < 0.65.5 -

II. Public POCs for CVE-2026-55615

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55615

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-55615 (1)

Vendor Advisories for CVE-2026-55615 (1)

Same Patch Batch · langroid · 2026-07-09 · 6 CVEs total

CVE-2026-54769 10.0 CRITICAL Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in Ta
CVE-2026-54771 8.1 HIGH Langroid: handle_message() executes user-supplied tool JSON without sender verification
CVE-2026-50181 7.1 HIGH Langroid: Path traversal in the file tools allows read/write outside configured current di
CVE-2026-54760 Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-
CVE-2026-50180 Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbit

IV. Related Vulnerabilities

V. Comments for CVE-2026-55615

No comments yet


Leave a comment