Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Langroid

First CVE: May 5, 2025Active for: 1 yearTotal CVEs: 4

Langroid is a Python framework designed to simplify the development of multi-agent AI applications, with its vulnerability profile centered on the core product and characterized by code-injection risks inherent to dynamic code generation and XML processing. The recurring weakness classes—improper code generation control and unrestricted XML entity reference handling—reflect the framework's integration of user input with executable contexts typical of agent-oriented and data-interchange layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
9.6
Avg CVSS Score
Higher Avg CVSS Score than 90% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Langroid over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2025
14 months ago
Most Recent CVE
Feb 4, 2026
170 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-25481CRITICAL
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call p
Feb 4, 20269.630NONO
CVE-2025-46724CRITICAL
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user i
May 20, 20259.828NONO
CVE-2025-46725CRITICAL
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs
May 20, 20259.826NONO
CVE-2025-46726CRITICAL
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untru
May 5, 20259.126NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network4 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Langroid.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Langroid — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Langroid's Products

View all 1 CNAs →

Top CWEs