CVE-2025-46724 Information

Description

Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15 TableChatAgent uses pandas eval(). If fed by untrusted user input like the case of a public-facing LLM application it may be vulnerable to code injection. Langroid 0.53.15 sanitizes input to TableChatAgent by default to tackle the most common attack vectors and added several warnings about the risky behavior in the project documentation.

Reference

https://github.com/langroid/langroid/commit/0d9e4a7bb3ae2eef8d38f2e970ff916599a2b2a6 https://github.com/langroid/langroid/security/advisories/GHSA-jqq5-wc57-f8hj https://github.com/langroid/langroid/security/advisories/GHSA-jqq5-wc57-f8hj

Share on: