Langroid fixed CVE-2026-55615 in Neo4jChatAgent, where LLM-generated Cypher queries were sent to Neo4j without validation before version 0.65.5. Because the query text could be influenced by direct user prompts or indirectly through retrieved RAG content, an attacker could abuse prompt-to-Cypher injection to read, modify, or destroy graph data. In Neo4j deployments with dangerous procedures enabled, including APOC or dbms.security features, the flaw could also expose the filesystem and enable operating system command execution.
A related Langroid patch also addressed the same defect pattern in ArangoChatAgent, where unvalidated AQL could be passed to the database driver. The remediation introduced a default-off allow_dangerous_operations control and validator functions that enforce read-only behavior on retrieval paths while blocking risky primitives such as Neo4j CALL db.*, LOAD CSV, APOC and dbms procedures, and ArangoDB namespace::func UDF calls unless explicitly enabled by an operator. The fix was described as mirroring the earlier SQLChatAgent bug tracked as CVE-2026-25879, and the project added 76 static unit tests to cover attack vectors, enforcement, bypass attempts, and false-positive handling.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-55615 was disclosed for a vulnerability affecting Langroid versions prior to 0.65.5 in which Neo4jChatAgent executed LLM-generated Cypher without validation, allowing prompt-injection-driven graph data access or destruction and possible OS-level impact when risky Neo4j procedures were enabled. The disclosure states the issue was fixed in version 0.65.5 and notes it mirrors the earlier SQLChatAgent bug tracked as CVE-2026-25879.
On 2026-06-15, a langroid commit addressed a security issue where LLM-generated Cypher and AQL queries were passed directly to database drivers without validation, enabling prompt-injection-driven data access or destruction and possible escalation in certain database configurations. The patch added a default-off allow_dangerous_operations gate, validator functions, and unit tests, and was associated with advisory GHSA-2pq5-3q89-j7cc.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.