CVE-2026-55585: QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed pa...
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.8.
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted gl...
Required action: Review and patch if applicable to your AI infrastructure.