CVE-2026-75062CWE-1188CWE-95

CVE-2026-75062

published August 26, 2026

CVSS
9.2
EPSS
0%
Percentile
13.8
In the wild
Unconfirmed
What it is

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in the default lf.query Python protocol in Google langfun versions prior to 0.1.2 allows remote unauthenticated attackers to execute arbitrary Python code in the context of the host application via crafted prompt inputs that cause the model to generate executable Python expressions evaluated without a sandbox.

The record
Technical detail
CVSS
9.2 · NONE
CVSS v4.0
9.2 · CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00231 · 13.8th percentile
Weaknesses
CWE-1188 · Initialization of a Resource with an Insecure Default; CWE-95 · Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Published
2026-08-26T19:16Z
References (3)
EPSS history
Timeline
  • 28 AUG 06:53Z
    EPSS moved — → 0%
    epss
  • 26 AUG 14:50Z
    Eval Injection in google/langfun via default lf.query protocol
    cvelistv5