logo

Critical Langroid Vulnerability Allows RCE via Prompt Injection

ID: f489a9e5-81e9-5e07-a1c4-4cd816986791

STIX ID: report--f489a9e5-81e9-5e07-a1c4-4cd816986791

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-06-01

Date Updated: 2026-06-01

Author: Ddos

...
...

Researchers discovered a critical RCE vulnerability in Langroid's SQLChatAgent that can be exploited via prompt injection to force dangerous database operations (such as PostgreSQL COPY FROM PROGRAM), enabling arbitrary system command execution, data exfiltration, data destruction, and lateral movement; a security patch is available in Langroid v0.63.0 which implements a SELECT-only allowlist and dialect-aware blocklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.