YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0025

Incident record

Google’s langfun ran model output through exec() by default

Severity
Critical
Status
Patched
Type
Prompt Injection
Target
Google langfun before 0.1.2
Actor
researcher
CVE
CVE-2026-75062

What happened

A CVE coordinated by Google’s own team records that langfun’s default lf.query Python protocol evaluated model output with exec() and no sandbox, so a crafted prompt could have the model emit an executable expression that ran inside the host application.

NVD scores it 9.2 critical under CVSS 4.0. Fixed in 0.1.2, with the underlying GitHub issue opened on 30 May 2026, so the gap between the problem being known and the record being published is about three months.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026