CVE-2026-50181: Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended wor...

Added to the CISA Known Exploited Vulnerabilities catalog on 10 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.1.

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `ReadFileTool` and `WriteFileTool` appear to treat `curr_dir` as the intended working-directory boundary for file operations. However, the tools only change the process working dire...

Required action: Review and patch if applicable to your AI infrastructure.