CVE-2026-75062
Eval Injection in google/langfun via default lf.query protocol
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host application via crafted prompt inputs that cause the model to generate executable Python expressions evaluated without a sandbox.
| CWE | CWE-95 CWE-1188 |
| Vendor | |
| Product | langfun |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for google langfun
Be the first to know when new unknown vulnerabilities affecting google langfun are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Google / langfun
0.0.1 < 0.1.2