Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-75062: Eval Injection in Google langfun

An eval injection vulnerability in Google langfun's lf.query protocol allows remote attackers to execute arbitrary Python code via crafted prompt inputs. The vulnerability affects versions prior to 0.1.2.

Disclosed 26 August 2026 · Record updated 13 September 2026

Impact

Remote unauthenticated attackers can execute arbitrary Python code in the context of the host application

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75062