HighVulnerability
GHSA-pw95-88fg-3j6f: Langroid Allows XXE Injection via XMLToolMessage
- Identifiers
- CVE-2025-46726GHSA-pw95-88fg-3j6f
- Published
- Record updated
- Affected
- langroid < 0.53.4
- Fixed in
- 0.53.4
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.6%
Summary
Langroid's XMLToolMessage class parses untrusted XML with lxml and no safeguards, so an LLM application using it can be exposed to denial of service through quadratic blowup payloads and to disclosure of local files through external entity declarations, which lxml processes by default. The advisory includes a proof-of-concept nested-entity payload that expands exponentially and can crash the application.
Mitigation
Fixed in Langroid 0.53.4, which initializes XMLParser with flags that disable entity resolution, DTD loading, and network access to prevent XXE, billion laughs, and external DTD attacks.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- langroidPyPILLM dependency since 2023-07-14
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories