Skip to content
LangChainGHSA-5chr-fjjv-38qv

langchain-core allows unauthorized users to read arbitrary files from the host file system

Medium5.3CVE-2024-10940 · Published Mar 20, 2025 · updated Jul 7, 2026

A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain-core
PyPI
>= 0.1.17, < 0.1.530.1.53
>= 0.2.0, < 0.2.430.2.43
>= 0.3.0, < 0.3.150.3.15
Details and references

More LangChain advisories

All LangChain
Advisory
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High7.5Sep 4, 2025
LangChain Community SSRF vulnerability exists in RequestsToolkit component
High8.4Jun 23, 2025
Langchain SQL Injection vulnerability
Low4.9Oct 29, 2024
Langchain Path Traversal vulnerability
Medium6.5Oct 29, 2024
@langchain/community SQL Injection vulnerability
Low4.9Oct 29, 2024
LangChain Experimental Eval Injection vulnerability
Critical9.8Sep 19, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.