Skip to content
LangChainGHSA-hc5w-c9f8-9cc4

Langchain Path Traversal vulnerability

Medium6.5CVE-2024-7774 · Published Oct 29, 2024 · updated Aug 7, 2026

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read `.txt` files, and delete files. The vulnerability is exploited through the `setFileContent`, `getParsedFile`, and `mdelete` methods, which do not properly sanitize user input.

GitHub advisory

Affected versions

PackageAffectedFixed in
langchain
npm
< 0.2.190.2.19
Details and references

More LangChain advisories

All LangChain
Advisory
Langchain SQL Injection vulnerability
Low4.9Oct 29, 2024
@langchain/community SQL Injection vulnerability
Low4.9Oct 29, 2024
LangChain Experimental Eval Injection vulnerability
Critical9.8Sep 19, 2024
LangChain pickle deserialization of untrusted data
High5.2Sep 17, 2024
langchain-experimental vulnerable to Arbitrary Code Execution
Critical8.5Jul 15, 2024
langchain_experimental Code Execution via Python REPL access
High7.8Jun 16, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.