THREAT OPS › Threat News › [NVD] CVE-2026-55585 (HIGH 8.8) — QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() with
[NVD] CVE-2026-55585 (HIGH 8.8) — QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() with
CVE-2026-55585 CVSS: 8.8 HIGH Published: 2026-08-25T17:17:32.903
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces,
Indicators of compromise
- CVE-2026-55585cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-55585