CVE-2026-55585P2HIGHCVSS 8.8fixed in 5.1.22026-08-25
CVE-2026-55585 [HIGH] CWE-94 CVE-2026-55585: QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces, allowing Python eval
nvd