Critical Langroid Vulnerability Allows RCE via Prompt Injection
ID: f489a9e5-81e9-5e07-a1c4-4cd816986791
STIX ID: report--f489a9e5-81e9-5e07-a1c4-4cd816986791
Feed Name: securityonline.info
Threat Score
Researchers discovered a critical RCE vulnerability in Langroid's SQLChatAgent that can be exploited via prompt injection to force dangerous database operations (such as PostgreSQL COPY FROM PROGRAM), enabling arbitrary system command execution, data exfiltration, data destruction, and lateral movement; a security patch is available in Langroid v0.63.0 which implements a SELECT-only allowlist and dialect-aware blocklist.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
