Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 26 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host application via crafted prompt inputs that cause the model to generate executable Python expressions evaluated without a sandbox. | |
| Title | Eval Injection in google/langfun via default lf.query protocol | |
| Weaknesses | CWE-1188 CWE-95 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-08-26T15:38:02.455Z
Reserved: 2026-08-17T15:35:22.670Z
Link: CVE-2026-75062
Updated: 2026-08-26T15:37:58.264Z
Status : Received
Published: 2026-08-26T15:16:55.853
Modified: 2026-08-26T16:16:38.220
Link: CVE-2026-75062
No data.
OpenCVE Enrichment
Updated: 2026-08-26T17:15:04Z