PatchSiren

langroid CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL langroid CVE published 2026-07-10

CVE-2026-55615

The CVE record was published on 2026-07-10T00:16:33.867Z and has not been modified since then. The NVD entry is currently Received. This critical vulnerability in Langroid's Neo4jChatAgent allows attackers to inject malicious Cypher queries, potentially leading to unauthorized data access or modification, and in some cases, OS-command and filesystem access if APOC or dbms.security procedures are enabled o [truncated]

HIGH langroid CVE published 2026-07-10

CVE-2026-54771

CVE-2026-54771 is a vulnerability in the Langroid framework that allows direct tool invocation via raw JSON payloads when tools are registered with `use=False, handle=True`. This issue was fixed in version 0.65.3. The vulnerability arises when the application exposes a chat interface to untrusted users. Users of Langroid framework versions prior to 0.65.3 who expose chat interfaces to untrusted users shou [truncated]

CRITICAL langroid CVE published 2026-07-10

CVE-2026-54769

CVE-2026-54769 is a critical vulnerability in Langroid, a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a Sandbox Escape leading to Remote Code Execution (RCE) in its TableChatAgent and VectorStore capabilities. The vulnerability arises from an incomplete understanding of Python's execution model, allowing attackers to execute arbitrary code. [truncated]

CRITICAL langroid CVE published 2026-07-10

CVE-2026-54760

Langroid framework vulnerability CVE-2026-54760 allows SQL injection via bypass of regex blocklist. The CVE record was published on 2026-07-10T00:16:33.477Z and has not been modified since then. This critical vulnerability arises from a bypassable regex blocklist in the SQLChatAgent, which allows attackers to execute PostgreSQL functions, including the previously blocked pg_read_file function. The vulnera [truncated]

HIGH langroid CVE published 2026-07-10

CVE-2026-50181

Langroid's ReadFileTool and WriteFileTool are vulnerable to path traversal attacks. The tools change the process working directory to a user-supplied directory but fail to properly enforce that file operations remain within that directory. This allows attackers to access files outside the intended directory by supplying path traversal sequences. Affected applications may include those using Langroid file [truncated]

HIGH langroid CVE published 2026-07-10

CVE-2026-50180

The Langroid framework, used for building large-language-model-powered applications, has a SQL injection vulnerability. An attacker can exploit this vulnerability to read arbitrary files from the PostgreSQL host through ordinary SELECT queries, even with the agent's strict default configuration. This vulnerability affects Langroid framework users, especially those using SQLChatAgent. The vulnerability all [truncated]