NONE · 0

CVE-2026-75062

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated a...

Vulnerability Description

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host application via crafted prompt inputs that cause the model to generate executable Python expressions evaluated without a sandbox.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-75062?

CVE-2026-75062 is a documented vulnerability. Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated a...

How severe is CVE-2026-75062?

CVSS scoring is not yet available for CVE-2026-75062. Check NVD for updates.

Is there a patch for CVE-2026-75062?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.