THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-55585 (HIGH 8.8) — QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() with

[NVD] CVE-2026-55585 (HIGH 8.8) — QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() with

mednvdPublished 2026-08-25

CVE-2026-55585 CVSS: 8.8 HIGH Published: 2026-08-25T17:17:32.903

QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55585