CVE-2025-46726CRITICAL 9.1EPSS p40.2%

CVE-2025-46726CVE-2025-46726

Description

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.

Scoring

CVSS 3.19.1 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS0.52% probability of exploitation · percentile 40.2% · 2026-06-19T12:03:05Z
Published2025-05-05
Last modified2025-08-01

Underlying weaknesses· 1

CWE-611

References

  1. https://github.com/langroid/langroid/blob/df6227e6c079ec22bb2768498423148d6685acff/langroid/agent/xml_tool_message.py#L51-L52
  2. https://github.com/langroid/langroid/commit/36e7e7db4dd1636de225c2c66c84052b1e9ac3c3
  3. https://github.com/langroid/langroid/security/advisories/GHSA-pw95-88fg-3j6f

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of XML External Entity Referencecwe-6110%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-46725
CVE
CVE-2025-46724
CVE
CVE-2025-68664
CVE
CVE-2025-45150
CVE
CVE-2025-2828
CVE
CVE-2026-25481
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.