Junglewise Threat Intelligence

CVE-2026-50180: Langroid SQLChatAgent arbitrary file read via SQL blocklist bypass

CVE-2026-50180 · Severity: high · CVSS 4 · Published 2026-07-10

Technologies: Langroid. Vendors: PyPI.

Executive brief

Langroid is a framework used to build applications powered by Large Language Models (LLMs). A security flaw in its SQL database agent allows an attacker to trick the AI into running restricted database commands. This can lead to the unauthorized reading of sensitive files from the server hosting the database, potentially exposing configuration files, logs, or other private data.

Technical details

The `SQLChatAgent` in Langroid uses a regex-based blocklist (`_DANGEROUS_SQL_PATTERNS`) within its `_validate_query` method to prevent dangerous SQL operations. This blocklist fails to include several PostgreSQL file-disclosure functions such as `pg_read_file()`, `pg_stat_file()`, and `pg_ls_logdir()`, as well as SQL Server's `OPENDATASOURCE` and certain SQLite `ATTACH` syntax variations. Because these functions are executed within standard `SELECT` statements, they bypass the default `allowed_statement_types=['SELECT']` restriction. An attacker can exploit this via prompt injection or by influencing the LLM's input to generate malicious SQL queries that reach the SQLAlchemy engine. The issue is addressed in version 0.64.0 by expanding the regex patterns to cover these function families.

Affected products

  • langroid langroid < 0.64.0

Timeline

  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-07-10: disclosed: NVD publication date

References

Related threats