Executive brief
Langroid, a framework for building LLM-based applications, contains a vulnerability in its data analysis component that allows attackers to execute arbitrary commands on the underlying server. By providing a specially crafted request to the TableChatAgent, an attacker can bypass security filters intended to block malicious code. This could lead to a full system compromise, unauthorized data access, or service disruption.
Technical details
A Remote Code Execution (RCE) vulnerability exists in Langroid's TableChatAgent due to a bypass of the WAF implemented in `langroid/utils/pandas_utils.py`. The root cause is twofold: the `_literal_ok()` function returns `False` instead of raising an `UnsafeCommandError` on invalid input, and the system fails to restrict access to dangerous Python dunder attributes like `__init__`, `__globals__`, and `__builtins__`. An attacker can chain whitelisted DataFrame methods to access the `eval` builtin and execute arbitrary shell commands. This vulnerability is a bypass of the fix for CVE-2025-46724 and is tracked as CVE-2026-25481. A patch is available in version 0.59.32.
Affected products
- langroid langroid <= 0.59.31
Timeline
- 2026-02-01: patched: Fixed in version 0.59.32
- 2026-02-02: advisory: GHSA-x34r-63hx-w57f published