Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242769
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048720
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229271
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19650
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2576
PyPI/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
13 Jul
Fix available
Severity - 9.2 (Critical)
PYSEC-2026-2579
PyPI/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
13 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-2581
PyPI/langroid
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
13 Jul
Fix available
Severity - 10.0 (Critical)
PYSEC-2026-2577
PyPI/langroid
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
13 Jul
Fix available
Severity - 9.3 (Critical)
PYSEC-2026-2580
PyPI/langroid
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
13 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-2578
PyPI/langroid
Langroid: Path traversal in the file tools allows read/write outside configured current directory
13 Jul
Fix available
Severity - 7.1 (High)
CVE-2026-54771
github.com/langroid/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
09 Jul
Fix available
Severity - 8.1 (High)
CVE-2026-54769
github.com/langroid/langroid
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
09 Jul
Fix available
Severity - 10.0 (Critical)
CVE-2026-54760
github.com/langroid/langroid
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
09 Jul
Fix available
Severity - 9.3 (Critical)
CVE-2026-50181
github.com/langroid/langroid
Langroid: Path traversal in the file tools allows read/write outside configured current directory
09 Jul
Fix available
Severity - 7.1 (High)
CVE-2026-50180
github.com/langroid/langroid
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
09 Jul
Fix available
Severity - 8.7 (High)
CVE-2026-55615
github.com/langroid/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
09 Jul
Fix available
Severity - 9.2 (Critical)
PYSEC-2026-1531
PyPI/langroid
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
07 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-1532
PyPI/langroid
Langroid Allows XXE Injection via XMLToolMessage
07 Jul
Fix available
Severity - 7.8 (High)
GHSA-2pq5-3q89-j7cc
PyPI/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
06 Jul
Fix available
Severity - 9.2 (Critical)
GHSA-gjgq-w2m6-wr5q
PyPI/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
06 Jul
Fix available
Severity - 8.1 (High)
Load more...
Vulnerability Database - OSV