CVE-2026-75062: Eval Injection in Google langfun
An eval injection vulnerability in Google langfun's lf.query protocol allows remote attackers to execute arbitrary Python code via crafted prompt inputs. The vulnerability affects versions prior to 0.1.2.
Disclosed 26 August 2026 · Record updated 13 September 2026
Impact
Remote unauthenticated attackers can execute arbitrary Python code in the context of the host application
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-75062
