Eval Injection Vulnerability in Google Langfun Product
CVE-2026-75062
9.2CRITICAL
What is CVE-2026-75062?
An Eval Injection vulnerability exists in the default lf.query Python protocol of Google Langfun versions before 0.1.2. This flaw permits remote unauthenticated attackers to execute arbitrary Python code. By crafting specific prompt inputs, an attacker can manipulate the model into generating and evaluating executable Python expressions without the implementation of a secure sandbox, leading to potential unauthorized access and control over the host application.
Affected Version(s)
langfun 0.0.1 < 0.1.2