Langroid path traversal in file tools allowed read/write outside the configured current directory.
Primary advisory: GHSA-fg23-3346-88f5
GitHub advisory database: github.com/advisories/GHSA-fg23-3346-88f5
Researcher credit: @chaitanyagarware
| Field | Value |
|---|---|
| CVE | CVE-2026-50181 |
| GHSA | GHSA-fg23-3346-88f5 |
| Project | langroid/langroid |
| Package | langroid |
| Ecosystem | pip |
| Severity | High |
| CVSS | 7.1, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| Weaknesses | CWE-22, CWE-23 |
| Published | Repository advisory: 2026-05-28; GitHub advisory database: 2026-07-02 |
| NVD status | No record returned as of 2026-07-09 |
| CVE.org status | CVE Services API returned no record as of 2026-07-09 |
Langroid's ReadFileTool and WriteFileTool treated curr_dir as a working-directory boundary, but the tools changed the process working directory and then used user-controlled file paths without enforcing that the final resolved path stayed inside the configured directory.
In applications that expose Langroid file tools to an agent, delegated workflow, or user-controlled tool call, this could allow reads or writes outside the intended project/workspace directory.
| Package | Affected |
|---|---|
langroid |
<= 0.63.0 |
The repository advisory lists no known patched version. The GitHub advisory database later associated the issue with 0.64.0 as a patched version. Treat the upstream advisory as the primary source if this changes.
| Source | Status | Link |
|---|---|---|
| GitHub repository advisory | Published | GHSA-fg23-3346-88f5 |
| GitHub Advisory Database | Published | Global advisory |
| GitHub Advisory Database repository | Present | advisory-database JSON |
| NVD | Not indexed yet | NVD detail |
| CVE.org | Not indexed yet | CVE detail |
Tabll/gemnasium-dbincludes apypi/langroid/CVE-2026-50181.ymlentry.opencve/opencve-kbincludes a2026/CVE-2026-50181.jsonentry.cyberdudebivash/cyberdudebivash-bloghas generated HTML/posts forCVE-2026-50181.RogoLabs/consensus-engineincludes a data file for this CVE.Agent-Threat-Rule/agent-threat-rulesincludes a proposal forGHSA-fg23-3346-88f5.
This repository is a public index and portfolio landing page. It intentionally summarizes the vulnerability and links to authoritative records instead of copying full proof-of-concept exploit scripts.