Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging XMLToolMessage class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-611"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46726.json"
}{
"cpe": "cpe:2.3:a:langroid:langroid:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.53.4"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}