Vulnerabilidades em langroid
11 resultadosAnálise Vexday
Langroid registra 11 vulnerabilidades no Vexday, com 6 em nível crítico e 7 publicadas nos últimos 90 dias, indicando atividade recente significativa. Nenhuma vulnerabilidade está sob exploração ativa documentada (KEV), mas a predominância de CWE-94 (execução de código não confiável) sinaliza risco estrutural elevado que merece atenção prioritária em ambientes de produção.
CVE-2025-46724CRITICALLangroid has a Code Injection vulnerability in TableChatAgentEPSS 0.7%CVE-2026-25481CRITICALLangroid has WAF Bypass Leading to RCE in TableChatAgentEPSS 0.6%CVE-2026-54769CRITICALLangroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgentEPSS 0.6%CVE-2025-46726HIGHLangroid Vulnerable to XXE Injection via XMLToolMessageEPSS 0.6%CVE-2026-50180HIGHLangroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readEPSS 0.6%CVE-2026-54760CRITICALLangroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file callsEPSS 0.6%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.6%CVE-2025-46725HIGHLangroid has a Code Injection vulnerability in LanceDocChatAgent through vector_storeEPSS 0.5%CVE-2026-55615CRITICALLangroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879EPSS 0.4%CVE-2026-54771HIGHLangroid: handle_message() executes user-supplied tool JSON without sender verificationEPSS 0.3%CVE-2026-50181HIGHLangroid: Path traversal in the file tools allows read/write outside configured current directoryEPSS 0.2%