<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 07:46:47 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-54769 — Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-54769</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langroid&lt;/p&gt;
&lt;p&gt;Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python&amp;#39;s `eval()` function. However, this relies on an incomplete understanding of Python&amp;#39;s execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__(&amp;#39;os&amp;#39;).system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system. Version 0.65.2 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; langroid&lt;/p&gt;
&lt;p&gt;Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python&amp;#39;s `eval()` function. However, this relies on an incomplete understanding of Python&amp;#39;s execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__(&amp;#39;os&amp;#39;).system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system. Version 0.65.2 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-54769</guid>
    </item>
    <item>
      <title>GHSA-q9p7-wqxg-mrhc — Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-q9p7-wqxg-mrhc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langroid&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python&amp;#39;s `eval()` function. However, this relies on an incomplete understanding of Python&amp;#39;s execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__(&amp;#39;os&amp;#39;).system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system.&lt;/p&gt;
&lt;p&gt;### Details
The root cause lies in how the framework evaluates generated Python code without a proper restricted environment.
Specifically, in `/langroid/agent/special/table_chat_agent.py` around line 239:
```python
# The `vars` mapping does not proactively overwrite or remove `__builtins__`
# The empty `{}` locals parameter provides false security. 
eval_result = eval(code, vars, {})
```
And similarly in `/langroid/vector_store/base.py` around line 225:
```python
result = eval(code, vars, {})
```
A…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langroid&lt;/p&gt;
&lt;p&gt;### Advisory Details
**Title**: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent&lt;/p&gt;
&lt;p&gt;**Description**:
### Summary
Langroid is vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python&amp;#39;s `eval()` function. However, this relies on an incomplete understanding of Python&amp;#39;s execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__(&amp;#39;os&amp;#39;).system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system.&lt;/p&gt;
&lt;p&gt;### Details
The root cause lies in how the framework evaluates generated Python code without a proper restricted environment.
Specifically, in `/langroid/agent/special/table_chat_agent.py` around line 239:
```python
# The `vars` mapping does not proactively overwrite or remove `__builtins__`
# The empty `{}` locals parameter provides false security. 
eval_result = eval(code, vars, {})
```
And similarly in `/langroid/vector_store/base.py` around line 225:
```python
result = eval(code, vars, {})
```
A…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-q9p7-wqxg-mrhc</guid>
    </item>
  </channel>
</rss>
