CVE-2026-75062: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python pr
Summary
Google's langfun library (versions before 0.1.2) has a vulnerability where eval injection (a flaw where untrusted code is executed without safety checks) allows attackers to run arbitrary Python code by sending specially crafted prompts to the AI model. The vulnerability exists because the system evaluates Python expressions generated by the model without using a sandbox (an isolated environment that restricts what code can do).
Solution / Mitigation
Update Google langfun to version 0.1.2 or later.
Vulnerability Details
EPSS: 0.0%
August 26, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75062
First tracked: August 26, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 95%