CVE-2026-55443
- EPSS 0.17%
- Veröffentlicht 22.06.2026 17:21:46
- Zuletzt bearbeitet 26.06.2026 20:05:46
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confine the resolved path to the intended root directo...
CVE-2026-44843
- EPSS 0.41%
- Veröffentlicht 26.05.2026 19:47:35
- Zuletzt bearbeitet 29.05.2026 19:48:48
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad ob...
CVE-2026-27795
- EPSS 0.21%
- Veröffentlicht 25.02.2026 17:30:01
- Zuletzt bearbeitet 13.04.2026 14:15:35
LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allo...
CVE-2026-26013
- EPSS 0.38%
- Veröffentlicht 10.02.2026 21:51:07
- Zuletzt bearbeitet 17.03.2026 20:30:07
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the ChatOpenAI.get_num_tokens_from_messages() method fetches arbitrary image_url values without validation when computing token counts for vision-enabled mode...
CVE-2024-58340
- EPSS 0.41%
- Veröffentlicht 12.01.2026 23:05:00
- Zuletzt bearbeitet 21.01.2026 17:57:56
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone ...
CVE-2025-65106
- EPSS 0.47%
- Veröffentlicht 21.11.2025 21:43:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python objec...
CVE-2025-8709
- EPSS 0.16%
- Veröffentlicht 26.10.2025 05:38:55
- Zuletzt bearbeitet 15.04.2026 00:35:42
A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of...
CVE-2025-6985
- EPSS 0.61%
- Veröffentlicht 06.10.2025 17:58:29
- Zuletzt bearbeitet 15.04.2026 00:35:42
The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are...
CVE-2025-46059
- EPSS 0.67%
- Veröffentlicht 29.07.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: t...
- EPSS 14.06%
- Veröffentlicht 23.06.2025 20:42:28
- Zuletzt bearbeitet 16.07.2025 19:46:41
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27....