CVE Tracker

CVE-2026-25879 @ morris

Status
does_not_affect
Priority
7.96
Match score
2.5
Risk
RCE
CVSS
9.8 CRITICAL
Reason
packages: filesystem
Created
2026-08-02T02:52:05Z
Updated
2026-08-02T08:43:39Z
Closed
2026-08-02T08:43:39Z

Package interrogation (copy)

Run on the host — click to copy a command. RPM

PackageCommands
filesystem

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: filesystem

SystemMatchesTicket for CVE-2026-25879
morris emacs-filesystem 24.3; filesystem 3.2; firebird-filesystem 2.5.9.27139.0; firewalld-filesystem 0.6.3; fontpackages-filesystem 1.44; plesk-libboost-filesystem1.65 1.65.1; plesk-libboost-filesystem1.74 1.74.0.1; plesk-libboost-filesystem1.82 1.82.0 (+1 more) does_not_affect open
mufasa emacs-filesystem 24.3; filesystem 3.2; firebird-filesystem 2.5.9.27139.0; firewalld-filesystem 0.6.3; fontpackages-filesystem 1.44; libreport-filesystem 2.1.11; plesk-libboost-filesystem1.74 1.74.0.1; plesk-libboost-filesystem1.82 1.82.0 (+2 more) does_not_affect open
Helios libboost-filesystem1.74.0 1.74.0-9 none
Saiph libboost-filesystem1.55.0 1.55.0+dfsg-3; libboost-filesystem1.62.0 1.62.0+dfsg-4 none

Same product CVEs in your queue

Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.

CVECVSSKEVSystemsStatus MatchedAlready related
CVE-2026-67429 10.0 morris, mufasa does_not_affect filesystem
CVE-2026-45661 9.9 morris, mufasa does_not_affect filesystem
CVE-2026-68770 9.8 morris, mufasa does_not_affect filesystem
CVE-2025-40212 9.8 morris, mufasa not_applicable filesystem
CVE-2026-36829 9.8 morris, mufasa does_not_affect filesystem
CVE-2026-47162 8.8 Archive, Janus, Library, Matrix, Saiph accepted_risk filesystem
CVE-2023-4692 7.5 Archive, Janus, Library, Saiph, morris accepted_risk, fixed filesystem

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
CloudLinux release 7.9 (Boris Yegorov) (7.9) · cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64
kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
mufasa does_not_affect 7.96 2026-08-02T08:43:54Z Open

Description

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. When configured with a database role that has privileges enabling code execution or filesystem access (e.g., PostgreSQL pg_execute_server_program, MySQL FILE, MSSQL xp_cmdshell), an attacker who can shape the agent's input — including indirectly via data returned to the LLM — can coerce execution of dialect-specific primitives such as `COPY ... FROM PROGRAM`, achieving RCE on the database host. Fixed in v0.63.0 by defaulting SQLChatAgent to a SELECT-only sqlglot-parsed statement allowlist with a dialect-aware dangerous-pattern blocklist; allow_dangerous_operations=True restores the previous unrestricted behavior for trusted deployments.

Determination

no product

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

Mitigation log

2026-08-02T08:43:39Z — does_not_affect
no product

References

NVD: CVE-2026-25879