langroid vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55615Criticallangroid: Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring…CVE-2026-54771Highlangroid: Langroid: handle_message() executes user-supplied tool JSON without sender verification CVE-2026-54769Criticallangroid: Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgentCVE-2026-54760Criticallangroid: Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file callsCVE-2026-50180Highlangroid: Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readCVE-2026-50181Highlangroid: Langroid: Path traversal in the file tools allows read/write outside configured current directoryCVE-2026-25879Criticallangroid: Langroid has Prompt to SQL Injection, Leading to RCECVE-2026-25481Criticallangroid: Langroid has WAF Bypass Leading to RCE in TableChatAgentCVE-2025-46725Highlangroid: Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_storeCVE-2025-46724Criticallangroid: Langroid has a Code Injection vulnerability in TableChatAgentCVE-2025-46726Highlangroid: Langroid Allows XXE Injection via XMLToolMessage

Stop the waste.
Protect your environment with Kodem.