Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

langroid — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting langroid. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Langroid is an AI framework for building language model applications, primarily used for developing conversational agents and text processing tools. Historically, it has been susceptible to remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities, often stemming from improper input validation and insecure deserialization. The framework's dynamic code execution capabilities have introduced additional risks, with privilege escalation occurring in certain configurations. While no major public incidents have been widely reported, the four documented CVEs highlight consistent patterns of insecure coding practices, particularly in how user-supplied data is handled and executed within the application's runtime environment.

Top products by langroid: langroid
CVE ID Title CVSS Severity Published
CVE-2026-54771 Langroid: handle_message() executes user-supplied tool JSON without sender verification — langroid CWE-75 8.1 High 2026-07-09
CVE-2026-54769 Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent — langroid CWE-94 10.0 Critical 2026-07-09
CVE-2026-54760 Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls — langroid CWE-22 - - 2026-07-09
CVE-2026-50181 Langroid: Path traversal in the file tools allows read/write outside configured current directory — langroid CWE-22 7.1 High 2026-07-09
CVE-2026-50180 Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read — langroid CWE-22 - - 2026-07-09
CVE-2026-55615 Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879 — langroid CWE-74 - - 2026-07-09
CVE-2026-25879 Langroid has Prompt to SQL Injection, Leading to RCE — langroid CWE-89 9.8 Critical 2026-06-01
CVE-2026-25481 Langroid has WAF Bypass Leading to RCE in TableChatAgent — langroid CWE-94 9.1AI Critical AI 2026-02-04
CVE-2025-46725 Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store — langroid CWE-94 10.0AI Critical AI 2025-05-20
CVE-2025-46724 Langroid has a Code Injection vulnerability in TableChatAgent — langroid CWE-94 9.8 Critical 2025-05-20
CVE-2025-46726 Langroid Vulnerable to XXE Injection via XMLToolMessage — langroid CWE-611 8.1AI High AI 2025-05-05

This page lists every published CVE security advisory associated with langroid. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.