CVE-2025-46725·Python vulnerability
Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, an attacker may be able to make the agent run malicious commands through `QueryPlan.dataframe_calc]`) compromising the host system. Langroid 0.53.15 sanitizes input to the affected function by default to tackle the most common attack vectors, and added several warnings about the risky behavior in the project documentation.
- Severity
- critical
- Software
- Python
- Fixed in
- 0.53.15
- Published
- 2025-05-20
Affected versions
Until: 0.53.15
Fixed in: 0.53.15
How to fix this CVE
Update the Langroid framework to version 0.53.15 or later to patch the unsafe pandas eval() execution vulnerability in LanceDocChatAgent. This version implements input sanitization to prevent malicious code injection through the QueryPlan.dataframe_calc parameter. Review your application's use of compute_from_docs() and consider implementing additional input validation layers beyond the default sanitization.
sudo dnf update python3-langroid || pip3 install --upgrade langroid>=0.53.15Defensia detects this vulnerability
How to check if you are affected
- Check installed Langroid version: pip3 show langroid | grep Version
- Verify if LanceDocChatAgent is instantiated in your codebase: grep -r 'LanceDocChatAgent' /path/to/your/app
- Search application logs for compute_from_docs() calls with unexpected parameters: grep -i 'compute_from_docs\|dataframe_calc' /var/log/app.log
- After patching, confirm version: pip3 show langroid | grep Version should show 0.53.15 or higher
FAQ
What is CVE-2025-46725?
CVE-2025-46725 is a critical remote code execution vulnerability in Langroid's LanceDocChatAgent that exposes unsafe pandas eval() functionality, allowing attackers to execute arbitrary system commands through malicious dataframe calculation parameters.
Is CVE-2025-46725 being actively exploited?
No, CVE-2025-46725 is not listed in the CISA Known Exploited Vulnerabilities catalog and no public exploits have been disclosed, but the critical CVSS 9.8 score warrants immediate patching.
What versions of Python are affected by CVE-2025-46725?
This vulnerability affects Langroid versions prior to 0.53.15 running on any Python 3.x installation. The issue resides in the Langroid framework, not Python itself.
How do I check if my server is vulnerable to CVE-2025-46725?
Run 'pip3 show langroid' and check if the Version is below 0.53.15. If Langroid is not installed or your version is 0.53.15+, you are not vulnerable.
Does Defensia detect CVE-2025-46725?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Langroid is installed on a monitored server, CVE-2025-46725 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-46725. Free for 1 server.
Get started free