Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2233088
AlmaLinux
5964
Alpaquita
16124
Alpine
4635
Android
3677
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9476
Chainguard
1043375
CleanStart
5235
CRAN
14
crates.io
2747
Debian
68820
Echo
7730
GHC
3
GIT
108734
GitHub Actions
55
Go
9317
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6233
Maven
7048
MinimOS
147720
npm
229081
NuGet
1869
opam
29
openEuler
8900
openSUSE
14526
OSS-Fuzz
4015
Packagist
7100
Pub
11
PyPI
25416
Red Hat
23452
Rocky Linux
4332
Root
19620
RubyGems
5326
SUSE
23401
SwiftURL
60
TuxCare
9809
Ubuntu
65806
VSCode
21
Wolfi
292794
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2576
PyPI/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
13 Jul
Fix available
Severity - 9.2 (Critical)
PYSEC-2026-2579
PyPI/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
13 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-2581
PyPI/langroid
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
13 Jul
Fix available
Severity - 10.0 (Critical)
PYSEC-2026-2577
PyPI/langroid
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
13 Jul
Fix available
Severity - 9.3 (Critical)
PYSEC-2026-2580
PyPI/langroid
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
13 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-2578
PyPI/langroid
Langroid: Path traversal in the file tools allows read/write outside configured current directory
13 Jul
Fix available
Severity - 7.1 (High)
CVE-2026-54771
github.com/langroid/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
09 Jul
Fix available
Severity - 8.1 (High)
CVE-2026-54769
github.com/langroid/langroid
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
09 Jul
Fix available
Severity - 10.0 (Critical)
CVE-2026-54760
github.com/langroid/langroid
Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls
09 Jul
Fix available
Severity - 9.3 (Critical)
CVE-2026-50181
github.com/langroid/langroid
Langroid: Path traversal in the file tools allows read/write outside configured current directory
09 Jul
Fix available
Severity - 7.1 (High)
CVE-2026-50180
github.com/langroid/langroid
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
09 Jul
Fix available
Severity - 8.7 (High)
CVE-2026-55615
github.com/langroid/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
09 Jul
Fix available
Severity - 9.2 (Critical)
PYSEC-2026-1531
PyPI/langroid
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
07 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-1532
PyPI/langroid
Langroid Allows XXE Injection via XMLToolMessage
07 Jul
Fix available
Severity - 7.8 (High)
GHSA-2pq5-3q89-j7cc
PyPI/langroid
Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879
06 Jul
Fix available
Severity - 9.2 (Critical)
GHSA-gjgq-w2m6-wr5q
PyPI/langroid
Langroid: handle_message() executes user-supplied tool JSON without sender verification
06 Jul
Fix available
Severity - 8.1 (High)
Load more...
Vulnerability Database - OSV