CVE-2026-25879: Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. Wh...
Added to the CISA Known Exploited Vulnerabilities catalog on 01 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access ...
Required action: Review and patch if applicable to your AI infrastructure.