CVE Database
/

CVE-2025-46726

Back to search

CVE-2025-46726

Published: May 5, 2025

Modified: May 5, 2025

PUBLISHED

Description

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.

VendorProductVersions

langroid

langroid

affected
< 0.53.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now