{"id":"CVE-2026-54771","aliases":["GHSA-gjgq-w2m6-wr5q","PYSEC-2026-2579"],"url":"https://o3.security/vulnerability/CVE-2026-54771","summary":"Langroid: handle_message() executes user-supplied tool JSON without sender verification","details":"Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`. Version 0.65.3 fixes the issue.","published":"2026-07-09T23:52:11.014Z","modified":"2026-08-12T03:51:47.017271923Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00278,"percentile":0.20341,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"langroid","fixedVersion":"0.65.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54771.json"},{"type":"ADVISORY","url":"https://github.com/langroid/langroid/security/advisories/GHSA-gjgq-w2m6-wr5q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54771"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.017271923Z"}}