Vulnerability Description
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langroid | Langroid | < 0.53.4 |
Related Weaknesses (CWE)
References
- https://github.com/langroid/langroid/blob/df6227e6c079ec22bb2768498423148d6685acProduct
- https://github.com/langroid/langroid/commit/36e7e7db4dd1636de225c2c66c84052b1e9aPatch
- https://github.com/langroid/langroid/security/advisories/GHSA-pw95-88fg-3j6fExploitVendor Advisory
FAQ
What is CVE-2025-46726?
CVE-2025-46726 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that ...
How severe is CVE-2025-46726?
CVE-2025-46726 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-46726?
Check the references section above for vendor advisories and patch information. Affected products include: Langroid Langroid.