Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-13410 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue. |
Github GHSA |
GHSA-pw95-88fg-3j6f | Langroid Allows XXE Injection via XMLToolMessage |
Fri, 01 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:langroid:langroid:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 05 May 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue. | |
| Title | Langroid Vulnerable to XXE Injection via XMLToolMessage | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-05T20:07:01.257Z
Reserved: 2025-04-28T20:56:09.084Z
Link: CVE-2025-46726
No data.
Status : Analyzed
Published: 2025-05-05T20:15:21.107
Modified: 2025-08-01T21:28:36.120
Link: CVE-2025-46726
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:22:20Z
EUVD
Github GHSA