Relative Path Traversal Affecting langroid package, versions [,0.64.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
0.23% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Relative Path Traversal vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-LANGROID-17816648
  • published4 Jul 2026
  • disclosed2 Jul 2026
  • creditUnknown

Introduced: 2 Jul 2026

CVE-2026-50181  (opens in a new tab)
CWE-22  (opens in a new tab)
CWE-23  (opens in a new tab)

How to fix?

Upgrade langroid to version 0.64.0 or higher.

Overview

langroid is a Harness LLMs with Multi-Agent Programming

Affected versions of this package are vulnerable to Relative Path Traversal through improper validation of user-supplied file paths in the ReadFileTool and WriteFileTool components. An attacker can access or modify files outside the intended working directory by supplying path traversal sequences such as '../filename', potentially exposing sensitive information or altering files outside the restricted directory. This is only exploitable if applications expose file tool functionality to untrusted input and rely on the current directory to enforce file access boundaries.

CVSS Base Scores

version 4.0
version 3.1