Sploitus

CVE-2026-54769

No indexed exploits for CVE-2026-54769 yet

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate LLM-generated tool messages with `full_eval=True`, they attempt to sandbox the execution by explicitly setting `locals` to an empty dictionary `{}` inside Python's `eval()` function. However, this relies on an incomplete understanding of Python's execution model. Because `__builtins__` is not explicitly scrubbed from the `globals` dictionary mapping, Python implicitly injects all built-ins during execution, granting full access to functions like `__import__('os').system()`. Since `TableChatAgent.pandas_eval()` executes external LLM outputs natively, this bypass permits any attacker providing prompt payload to achieve unauthenticated RCE on the host system. Version 0.65.2 patches the issue.

Affected products
Langroid
Fix
Available
CVSS 3.1
10.0 CRITICAL
EPSS
0.6% (47th percentile)
Weakness
CWE-94
NVD status
Deferred
Published
2026-07-09
CVE-2026-54769 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-54769 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-54769 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.