PT-2026-82206 · Pypi · Langfun

·

CVE-2026-75062

·

Published

2026-08-26

·

Updated

2026-08-27

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions langfun versions prior to 0.1.2
Description An Eval Injection occurs in the default lf.query Python protocol. This issue allows remote unauthenticated attackers to execute arbitrary Python code within the host application context. The flaw is triggered when crafted prompt inputs lead the model to generate executable Python expressions that are evaluated without a sandbox. Eval Injection is a flaw where untrusted input is passed to a code evaluation function, allowing the execution of unauthorized commands.
Recommendations Update langfun to version 0.1.2 or later. As a temporary mitigation, restrict the use of the lf.query protocol to prevent the evaluation of untrusted prompt inputs.

Exploit

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75062

Affected Products

Langfun