Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage` class may be exposed to untrusted XML input that could result in DoS and/or exposing local files with sensitive information. Version 0.53.4 fixes the issue.
CVSS
No CVSS.
References
Configurations
No configuration.
History
05 May 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-05 20:15
Updated : 2025-05-05 20:54
NVD link : CVE-2025-46726
Mitre link : CVE-2025-46726
CVE.ORG link : CVE-2025-46726
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference