Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Modified: 7/7/2026
package
pkg:pypi/langroid
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Modified: 7/7/2026
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Modified: 7/13/2026
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Modified: 7/13/2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
Modified: 7/13/2026
Langroid: handle_message() executes user-supplied tool JSON without sender verification
Modified: 7/13/2026
Langroid has a Code Injection vulnerability in TableChatAgent
Modified: 7/1/2026
Langroid has Prompt to SQL Injection, Leading to RCE
Modified: 7/1/2026
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
Modified: 7/13/2026
Langroid Allows XXE Injection via XMLToolMessage
Modified: 7/7/2026
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Modified: 7/13/2026
Langroid has WAF Bypass Leading to RCE in TableChatAgent
Modified: 7/1/2026
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Modified: 7/7/2026
Langroid Allows XXE Injection via XMLToolMessage
Modified: 7/7/2026
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
Modified: 7/13/2026
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
Modified: 7/13/2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
Modified: 7/13/2026
Langroid: handle_message() executes user-supplied tool JSON without sender verification
Modified: 7/13/2026
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
Modified: 7/13/2026
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
Modified: 7/13/2026
Langroid has a Code Injection vulnerability in TableChatAgent
Modified: 7/1/2026
Langroid has Prompt to SQL Injection, Leading to RCE
Modified: 7/1/2026
Langroid has WAF Bypass Leading to RCE in TableChatAgent
Modified: 7/13/2026