Skip to content
CriticalVulnerability

GHSA-x34r-63hx-w57f: Langroid has WAF Bypass Leading to RCE in TableChatAgent

Published
Record updated
View JSON
Affected
  • langroid <= 0.59.31
Fixed in
0.59.32
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.8%

Summary

Langroid versions up to and including 0.59.31 are affected by a bypass of the WAF in `langroid/utils/pandas_utils.py` that was added for CVE-2025-46724. Because `_literal_ok()` returns `False` instead of raising `UnsafeCommandError` on invalid input, and dunder attributes such as `__init__`, `__globals__` and `__builtins__` remain accessible, attacker-supplied input to the `pandas_eval` tool of `TableChatAgent` can reach the `eval` builtin. The source reports this allows arbitrary shell command execution on the server.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.