Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
References
Configurations
History
No history.
Information
Published : 2025-05-05 20:15
Updated : 2025-08-01 21:28
NVD link : CVE-2025-46726
Mitre link : CVE-2025-46726
CVE.ORG link : CVE-2025-46726
JSON object : View
Products Affected
langroid
- langroid
CWE
CWE-611
Improper Restriction of XML External Entity Reference
