VulnSea

langroid vulnerabilities

CVEs whose affected-version data names the langroid package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-55615Critical
2mo ago

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Midnightlangroid · langroidEPSS 0.46%via GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-54769Critical· 10.0
2mo ago

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Midnightlangroid · langroidEPSS 0.91%via GHSA
CVE-2026-54771High· 8.1
2mo ago

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Twilightlangroid · langroidEPSS 0.39%via GHSA
CVE-2026-50180High
2mo ago

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Twilightlangroid · langroidEPSS 0.69%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-25879Critical· 9.8
3mo ago

Langroid has Prompt to SQL Injection, Leading to RCE

Langroid has Prompt to SQL Injection, Leading to RCE

Midnightlangroid · langroidEPSS 0.55%via OSV
CVE-2026-25481Critical
7mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Midnightlangroid · langroidEPSS 0.66%via OSV
CVE-2025-46724Critical· 9.8
1y ago

Langroid has a Code Injection vulnerability in TableChatAgent

Langroid has a Code Injection vulnerability in TableChatAgent

Midnightlangroid · langroidEPSS 0.83%via OSV
CVE-2025-46725High
1y ago

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Twilightlangroid · langroidEPSS 0.53%via OSV
CVE-2025-46726High
1y ago

Langroid Allows XXE Injection via XMLToolMessage

Langroid Allows XXE Injection via XMLToolMessage

Twilightlangroid · langroidEPSS 0.62%via OSV
langroid vulnerabilities (CVEs) · VulnSea