Executive brief
Langroid Allows XXE Injection via XMLToolMessage
Affected products
- PyPI langroid
Junglewise Threat Intelligence
CVE-2025-46726 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: langroid (PyPI). Vendors: PyPI.
Langroid Allows XXE Injection via XMLToolMessage