Skip to content

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Critical severity GitHub Reviewed Published Jun 15, 2026 in langroid/langroid • Updated Jul 6, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts