{"data":{"id":"08c36733-b677-42e6-b4c6-e0adf8cc25c3","title":"CVE-2026-75062: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr","summary":"Google's langfun library (versions before 0.1.2) has a vulnerability where eval injection (a flaw where untrusted code is executed without safety checks) allows attackers to run arbitrary Python code by sending specially crafted prompts to the AI model. The vulnerability exists because the system evaluates Python expressions generated by the model without using a sandbox (an isolated environment that restricts what code can do).","solution":"Update Google langfun to version 0.1.2 or later.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75062","publishedAt":"2026-08-26T15:16:55.853Z","cveId":"CVE-2026-75062","cweIds":["CWE-95","CWE-1188"],"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Google"],"affectedVendorsRaw":["Google langfun"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-26T15:16:55.853Z","capecIds":["CAPEC-242"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":["AML.T0051"]}}