GHSA-x34r-63hx-w57f: Langroid has WAF Bypass Leading to RCE in TableChatAgent
- Identifiers
- CVE-2026-25481GHSA-x34r-63hx-w57f
- Published
- Record updated
- Affected
- langroid <= 0.59.31
- Fixed in
- 0.59.32
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.8%
Summary
Langroid versions up to and including 0.59.31 are affected by a bypass of the WAF in `langroid/utils/pandas_utils.py` that was added for CVE-2025-46724. Because `_literal_ok()` returns `False` instead of raising `UnsafeCommandError` on invalid input, and dunder attributes such as `__init__`, `__globals__` and `__builtins__` remain accessible, attacker-supplied input to the `pandas_eval` tool of `TableChatAgent` can reach the `eval` builtin. The source reports this allows arbitrary shell command execution on the server.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- langroidPyPILLM dependency since 2023-07-14
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading