Researchers disclosed CVE-2026-25879, a critical vulnerability in the Langroid Python framework that lets attackers use prompt injection to steer the SQLChatAgent component into executing malicious LLM-generated SQL. The flaw can bypass intended input restrictions and abuse database-specific primitives, potentially escalating from SQL manipulation to remote code execution on the database host. Reported impacts include arbitrary command execution, data exfiltration, destructive database changes, and possible lateral movement, and the issue was rated CVSS 9.8.
The exposure affects Langroid versions prior to 0.63.0 and is most severe when the application connects with highly privileged database roles, including capabilities such as PostgreSQL pg_execute_server_program, MySQL FILE, or MSSQL xp_cmdshell. Researchers also warned that exploitation may occur through indirect attacker influence over data returned to the LLM, not only through direct user prompts. Langroid patched the issue in version 0.63.0 by enforcing a strict SELECT-only allowlist parsed with sqlglot and adding a dialect-aware blocklist for dangerous patterns, while still permitting trusted deployments to restore broader behavior with allow_dangerous_operations=True.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Langroid patched the vulnerability in version 0.63.0 by making SQLChatAgent default to a strict SELECT-only allowlist parsed with sqlglot and adding a dialect-aware blocklist for dangerous patterns. The prior unrestricted behavior can still be re-enabled in trusted deployments with allow_dangerous_operations=True.
Researchers from Carnegie Mellon University and the University of Wisconsin–Madison discovered a critical prompt-injection flaw in Langroid's SQLChatAgent that could lead to remote code execution on the database host when dangerous database privileges were available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.