Skip to content

LangChain security advisories

47 advisories across LangChain, LangGraph

Company profile
DateAdvisory
Jun 17LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versions 0.3.14 and prior have unsafe URL path construction through unsanitized caller-supplied identifier values used in HTTP request paths for resource ope
CVE-2026-48776LangGraphCritical9.1fixed in 0.3.15
Jun 16LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-55443LangChainMedium5.1fixed in 1.3.9
May 13LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-45134LangChainHigh7.1fixed in 0.3.30
May 8LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-44843LangChainHigh8.2fixed in 0.3.85, 1.3.3
Apr 8LangChain has incomplete f-string validation in prompt templates
CVE-2026-40087LangChainMedium5.3fixed in 0.3.84, 1.2.28
Mar 27LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
CVE-2026-34070LangChainHigh7.5fixed in 1.2.22
Mar 5LangGraph checkpoint loading has unsafe msgpack deserialization
CVE-2026-28277LangGraphMedium6.8fixed in 1.0.10
Feb 25LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
CVE-2026-27795LangChainMedium4.1fixed in 1.1.18
Feb 11@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation
CVE-2026-26019LangChainMedium4.1fixed in 1.1.14
Feb 11LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2026-26013LangChainLow3.7fixed in 1.2.11
Dec 232025LangChain serialization injection vulnerability enables secret extraction
CVE-2025-68665LangChainHigh8.6fixed in 0.3.37, 0.3.80, 1.1.8, 1.2.3
Dec 232025LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
CVE-2025-68664LangChainCritical9.3fixed in 0.3.81, 1.2.5
Nov 202025LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
CVE-2025-65106LangChainHighfixed in 0.3.80, 1.0.7
Sep 42025Langchain Community Vulnerable to XML External Entity (XXE) Attacks
CVE-2025-6984LangChainHigh7.5fixed in 0.3.27
Jun 232025LangChain Community SSRF vulnerability exists in RequestsToolkit component
CVE-2025-2828LangChainHigh8.4fixed in 0.0.28
Mar 202025langchain-core allows unauthorized users to read arbitrary files from the host file system
CVE-2024-10940LangChainMedium5.3fixed in 0.1.53, 0.2.43, 0.3.15
Oct 292024Langchain SQL Injection vulnerability
CVE-2024-8309LangChainLow4.9fixed in 0.2.0, 0.2.19
Oct 292024@langchain/community SQL Injection vulnerability
CVE-2024-7042LangChainLow4.9fixed in 0.3.3
Oct 292024Langchain Path Traversal vulnerability
CVE-2024-7774LangChainMedium6.5fixed in 0.2.19
Sep 192024LangChain Experimental Eval Injection vulnerability
CVE-2024-46946LangChainCritical9.8no fix yet
Sep 172024LangChain pickle deserialization of untrusted data
CVE-2024-5998LangChainHigh5.2fixed in 0.2.4
Jul 152024langchain-experimental vulnerable to Arbitrary Code Execution
CVE-2024-21513LangChainCritical8.5fixed in 0.0.21
Jun 162024langchain_experimental Code Execution via Python REPL access
CVE-2024-38459LangChainHigh7.8fixed in 0.0.61
Jun 62024Denial of service in langchain-community
CVE-2024-2965LangChainMedium4.2fixed in 0.2.5
Jun 62024Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
CVE-2024-3095LangChainMedium4.8fixed in 0.2.9
Apr 162024langchain vulnerable to path traversal
CVE-2024-3571LangChainMedium6.5fixed in 0.0.353
Mar 262024LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-1455LangChainMedium5.9fixed in 0.1.35
Mar 42024LangChain directory traversal vulnerability
CVE-2024-28088LangChainLowfixed in 0.0.339, 0.1.30
Mar 12024A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It
CVE-2024-2057LangChainCritical9.8no fix yet
Feb 262024LangChain Experimental vulnerable to arbitrary code execution
CVE-2024-27444LangChainCritical9.8fixed in 0.0.52
Feb 262024langchain Server-Side Request Forgery vulnerability
CVE-2024-0243LangChainLow3.7fixed in 0.1.0
Oct 212023Langchain Server-Side Request Forgery vulnerability
CVE-2023-32786LangChainHigh7.5fixed in 0.0.329
Oct 212023Langchain SQL Injection vulnerability
CVE-2023-32785LangChainCritical9.8fixed in 0.0.247
Oct 192023LangChain Server Side Request Forgery vulnerability
CVE-2023-46229LangChainHigh8.8fixed in 0.0.317
Oct 92023langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method
CVE-2023-44467LangChainCritical9.8no fix yet
Sep 12023Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
CVE-2023-39631LangChainCritical9.8fixed in 0.0.308
Aug 222023langchain vulnerable to arbitrary code execution
CVE-2023-36281LangChainCritical9.8fixed in 0.0.312
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-38896LangChainCritical9.8fixed in 0.0.236
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-38860LangChainCritical9.8fixed in 0.0.247
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-39659LangChainCritical9.8fixed in 0.0.325
Aug 52023langchain Code Injection vulnerability
CVE-2023-36095LangChainCritical9.8fixed in 0.0.236
Jul 62023langchain vulnerable to arbitrary code execution
CVE-2023-36188LangChainCritical9.8fixed in 0.0.247
Jul 62023langchain SQL Injection vulnerability
CVE-2023-36189LangChainHigh7.5fixed in 0.0.247
Jul 32023langchain arbitrary code execution vulnerability
CVE-2023-36258LangChainCritical9.8fixed in 0.0.247
Jun 202023Langchain vulnerable to arbitrary code execution
CVE-2023-34541LangChainCritical9.8fixed in 0.0.247
Jun 142023Langchain OS Command Injection vulnerability
CVE-2023-34540LangChainCritical9.8fixed in 0.0.225
Apr 52023LangChain vulnerable to code injection
CVE-2023-29374LangChainCritical9.8no fix yet
About LangChain

Elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.