Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 05 May 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue. | |
Title | Langroid Vulnerable to XXE Injection via XMLToolMessage | |
Weaknesses | CWE-611 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-05T19:21:19.597Z
Updated: 2025-05-05T20:07:01.257Z
Reserved: 2025-04-28T20:56:09.084Z
Link: CVE-2025-46726

No data.

Status : Awaiting Analysis
Published: 2025-05-05T20:15:21.107
Modified: 2025-05-05T20:54:19.760
Link: CVE-2025-46726

No data.