CVE-2025-46726
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
- Langroid
- < 0.53.4
- Fix
- Available
- CVSS 3.1
- 9.1 CRITICAL
- EPSS
- 0.6% (44th percentile)
- Weakness
- CWE-611
- NVD status
- Analyzed
- Published
- 2025-05-05
CVE-2025-46726 at NVD
No indexed exploits for CVE-2025-46726 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-46726 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.