Security Advisory
CVE-2026-54771
8.1
HIGH
Vulnerability Description
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat interface to untrusted users may allow direct tool invocation via raw JSON payloads, even when tools are registered with `use=False, handle=True`. Version 0.65.3 fixes the issue.
Published Date
July 10, 2026
Official Source
NIST NVD Advisory