Langroid
This hub aggregates every CVE we track for Langroid, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
8
CVEs tracked
6
Critical
2
High
0
In CISA KEV
Severity distribution
CRITICAL6HIGH2
Monthly trend
0
0
0
0
0
0
0
0
0
3
0
0
0
0
0
0
0
0
1
0
0
0
1
3
2024-082026-07
Latest CVEs
The 8 most recently published vulnerabilities affecting Langroid.
- CVE-2026-54771Langroid: handle_message() executes user-supplied tool JSON without sender verification8.1
- CVE-2026-54769Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent10.0
- CVE-2026-50181Langroid: Path traversal in the file tools allows read/write outside configured current directory7.1
- CVE-2026-25879Langroid has Prompt to SQL Injection, Leading to RCE9.8
- CVE-2026-25481Langroid has WAF Bypass Leading to RCE in TableChatAgent9.6
- CVE-2025-46725Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store9.8
- CVE-2025-46724Langroid has a Code Injection vulnerability in TableChatAgent9.8
- CVE-2025-46726Langroid Vulnerable to XXE Injection via XMLToolMessage9.1
Product normalization is registry-driven with AI assist and human review. How it works