CVE-2026-54769

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python's `eval()` function. However, this relies on an incomplete understanding of Python's execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__('os').system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system. Version 0.65.2 patches the issue.
Configurations

No configuration.

History

10 Jul 2026, 15:16

Type Values Removed Values Added
References () https://github.com/langroid/langroid/security/advisories/GHSA-q9p7-wqxg-mrhc - () https://github.com/langroid/langroid/security/advisories/GHSA-q9p7-wqxg-mrhc -

10 Jul 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 00:16

Updated : 2026-07-10 15:49


NVD link : CVE-2026-54769

Mitre link : CVE-2026-54769

CVE.ORG link : CVE-2026-54769


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')