12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether langroid is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-25481
Langroid has WAF Bypass Leading to RCE in TableChatAgent
UNKNOWN
CVE-2025-46726
Langroid Allows XXE Injection via XMLToolMessage
UNKNOWN
CVE-2025-46725
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
UNKNOWN
CVE-2025-46726
Langroid Allows XXE Injection via XMLToolMessage
UNKNOWN
CVE-2025-46725
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
HIGH 7.1
CVE-2026-50181
Langroid: Path traversal in the file tools allows read/write outside configured current directory
UNKNOWN
CVE-2026-50180
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
CRITICAL 9.8
CVE-2026-25879
Langroid has Prompt to SQL Injection, Leading to RCE
CRITICAL 9.8
CVE-2025-46724
Langroid has a Code Injection vulnerability in TableChatAgent
UNKNOWN
CVE-2026-25481
Langroid has WAF Bypass Leading to RCE in TableChatAgent
CRITICAL 9.8
CVE-2026-25879
Langroid has Prompt to SQL Injection, Leading to RCE
CRITICAL 9.8
CVE-2025-46724
Langroid has a Code Injection vulnerability in TableChatAgent
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes