VulnSea

langroid has 11 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 6 in the last 90 days against 1 in the 90 before. The busiest recent month was July 2026 with 6. The median CVSS is 9.8 (critical), with 6 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-22 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
Last 90 days
6 prev 1

Products

  • langroid 11
11
Total CVEs
6
Critical
0
CISA KEV
0
Exploited

langroid vulnerabilities

CVEs affecting langroid, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-55615Critical
2mo ago

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Midnightlangroid · langroidEPSS 0.46%via GHSA
CVE-2026-54760Critical
2mo ago

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls

Midnightlangroid · langroidEPSS 0.65%via GHSA
CVE-2026-54769Critical· 10.0
2mo ago

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Midnightlangroid · langroidEPSS 0.91%via GHSA
CVE-2026-54771High· 8.1
2mo ago

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Langroid: handle_message() executes user-supplied tool JSON without sender verification

Twilightlangroid · langroidEPSS 0.39%via GHSA
CVE-2026-50180High
2mo ago

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

Twilightlangroid · langroidEPSS 0.69%via GHSA
CVE-2026-50181High· 7.1PoC
2mo ago

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Langroid: Path traversal in the file tools allows read/write outside configured current directory

Midnightlangroid · langroidEPSS 0.18%via GHSA
CVE-2026-25879Critical· 9.8
3mo ago

Langroid has Prompt to SQL Injection, Leading to RCE

Langroid has Prompt to SQL Injection, Leading to RCE

Midnightlangroid · langroidEPSS 0.55%via OSV
CVE-2026-25481Critical
7mo ago

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Langroid has WAF Bypass Leading to RCE in TableChatAgent

Midnightlangroid · langroidEPSS 0.66%via OSV
CVE-2025-46724Critical· 9.8
1y ago

Langroid has a Code Injection vulnerability in TableChatAgent

Langroid has a Code Injection vulnerability in TableChatAgent

Midnightlangroid · langroidEPSS 0.83%via OSV
CVE-2025-46725High
1y ago

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Twilightlangroid · langroidEPSS 0.53%via OSV
CVE-2025-46726High
1y ago

Langroid Allows XXE Injection via XMLToolMessage

Langroid Allows XXE Injection via XMLToolMessage

Twilightlangroid · langroidEPSS 0.62%via OSV
langroid vulnerabilities (CVEs) · VulnSea