{"id":"CVE-2026-50180","aliases":["GHSA-pmch-g965-grmr","PYSEC-2026-2580"],"url":"https://o3.security/vulnerability/CVE-2026-50180","summary":"Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read","details":"Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` in `langroid` ships a `_validate_query` defense-in-depth layer whose `_DANGEROUS_SQL_PATTERNS` regex blocklist enumerates dangerous SQL primitives by specific function name. The list misses the canonical PostgreSQL filesystem-disclosure family `pg_read_file()`, `pg_stat_file()`, `pg_ls_logdir()`, `pg_ls_waldir()`, `pg_current_logfile()` (and similar `SELECT`-shaped functions in the same family). It also leaves SQL Server `OPENDATASOURCE` and SQLite `ATTACH '<file>' AS x` (DATABASE keyword omitted) unblocked. An attacker able to shape the LLM's generated SQL (directly via prompt input or transitively via prompt-injection in data the LLM ingests) can read arbitrary files from the PostgreSQL host through ordinary `SELECT` queries, even with the agent's strict default configuration (`allow_dangerous_operations=False`, `allowed_statement_types=['SELECT']`). The payloads survive the statement-type allowlist (each is a `SELECT`) and pass through the regex blocklist (none of the function names match), then reach the live SQLAlchemy engine via `SQLChatAgent.run_query`. Version 0.64.0 contains a patch for the issue.","published":"2026-07-09T23:42:52.853Z","modified":"2026-08-12T03:51:20.404638245Z","cvss":null,"epss":{"score":0.00568,"percentile":0.4448,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"langroid","fixedVersion":"0.64.0"}],"fix":{"url":"https://github.com/langroid/langroid/commit/00b7dd7b79c5d03c94be284cf3459d98195ebfba","label":"langroid/langroid@00b7dd7"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50180.json"},{"type":"ADVISORY","url":"https://github.com/langroid/langroid/security/advisories/GHSA-pmch-g965-grmr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50180"},{"type":"FIX","url":"https://github.com/langroid/langroid/commit/00b7dd7b79c5d03c94be284cf3459d98195ebfba"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:20.404638245Z"}}