Skip to content
HighVulnerability

GHSA-pw95-88fg-3j6f: Langroid Allows XXE Injection via XMLToolMessage

Published
Record updated
View JSON
Affected
  • langroid < 0.53.4
Fixed in
0.53.4
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

Langroid's XMLToolMessage class parses untrusted XML with lxml and no safeguards, so an LLM application using it can be exposed to denial of service through quadratic blowup payloads and to disclosure of local files through external entity declarations, which lxml processes by default. The advisory includes a proof-of-concept nested-entity payload that expands exponentially and can crash the application.

Mitigation

Fixed in Langroid 0.53.4, which initializes XMLParser with flags that disable entity resolution, DTD loading, and network access to prevent XXE, billion laughs, and external DTD attacks.