Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-50181 — Curated landing page for CVE-2026-50181, documenting a Langroid path traversal vulnerability (CWE-22/23) with links to GHSA, NVD, and public database coverage. | Kitploit
Tools/GitHubGitHub/chaitanyagarware/cve-2026-50181
Vulnerability AnalysisInformation GatheringWeb SecurityLearning & EducationCurated Resources
GitHubchaitanyagarware/cve-2026-50181

CVE-2026-50181

Curated landing page for CVE-2026-50181, documenting a Langroid path traversal vulnerability (CWE-22/23) with links to GHSA, NVD, and public database coverage.

View Repository
Website
12 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-50181

Langroid path traversal in file tools allowed read/write outside the configured current directory.

Primary advisory: GHSA-fg23-3346-88f5
GitHub advisory database: github.com/advisories/GHSA-fg23-3346-88f5
Researcher credit: @chaitanyagarware

At a Glance

FieldValue
CVECVE-2026-50181
GHSAGHSA-fg23-3346-88f5
Projectlangroid/langroid
Packagelangroid
Ecosystempip
SeverityHigh
CVSS7.1, CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
WeaknessesCWE-22, CWE-23
PublishedRepository advisory: 2026-05-28; GitHub advisory database: 2026-07-02
NVD statusNo record returned as of 2026-07-09
CVE.org statusCVE Services API returned no record as of 2026-07-09

Summary

Langroid's ReadFileTool and WriteFileTool treated curr_dir as a working-directory boundary, but the tools changed the process working directory and then used user-controlled file paths without enforcing that the final resolved path stayed inside the configured directory.

In applications that expose Langroid file tools to an agent, delegated workflow, or user-controlled tool call, this could allow reads or writes outside the intended project/workspace directory.

Affected Versions

PackageAffected
langroid<= 0.63.0

Fixed Versions

The repository advisory lists no known patched version. The GitHub advisory database later associated the issue with 0.64.0 as a patched version. Treat the upstream advisory as the primary source if this changes.

Public Database Coverage

SourceStatusLink
GitHub repository advisoryPublishedGHSA-fg23-3346-88f5
GitHub Advisory DatabasePublishedGlobal advisory
GitHub Advisory Database repositoryPresentadvisory-database JSON
NVDNot indexed yetNVD detail
CVE.orgNot indexed yetCVE detail

Additional Public Mentions Found

  • Tabll/gemnasium-db includes a pypi/langroid/CVE-2026-50181.yml entry.
  • opencve/opencve-kb includes a 2026/CVE-2026-50181.json entry.
  • cyberdudebivash/cyberdudebivash-blog has generated HTML/posts for CVE-2026-50181.
  • RogoLabs/consensus-engine includes a data file for this CVE.
  • Agent-Threat-Rule/agent-threat-rules includes a proposal for GHSA-fg23-3346-88f5.

Disclosure Note

This repository is a public index and portfolio landing page. It intentionally summarizes the vulnerability and links to authoritative records instead of copying full proof-of-concept exploit scripts.

Download Tool