{"data":{"id":"957a0f6f-3e0e-4d54-9c76-4451754f98aa","title":"GHSA-pw95-88fg-3j6f: Langroid Allows XXE Injection via XMLToolMessage","summary":"Langroid's XMLToolMessage class parses untrusted XML with lxml and no safeguards, so an LLM application using it can be exposed to denial of service through quadratic blowup payloads and to disclosure of local files through external entity declarations, which lxml processes by default. The advisory includes a proof-of-concept nested-entity payload that expands exponentially and can crash the application.","solution":"Fixed in Langroid 0.53.4, which initializes XMLParser with flags that disable entity resolution, DTD loading, and network access to prevent XXE, billion laughs, and external DTD attacks.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-pw95-88fg-3j6f","publishedAt":"2025-05-05T20:40:44.000Z","cveId":"CVE-2025-46726","cweIds":["CWE-611"],"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["denial_of_service","other"],"issueType":"vulnerability","affectedPackages":["langroid@< 0.53.4 (fixed: 0.53.4)"],"affectedPackageNames":["langroid"],"affectedPackageRefs":["pypi:langroid"],"affectedVendors":[],"affectedVendorsRaw":["Langroid"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00648,"epssCheckedAt":"2026-10-10T04:57:12.751Z","kevDateAdded":null,"advisoryAliases":["GHSA-pw95-88fg-3j6f"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-05-05T20:40:44.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}