| Jun 16 | LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders CVE-2026-55443Medium5.1fixed in 1.3.9 | Medium5.1 | 1.3.9 |
| May 13 | LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning CVE-2026-45134High7.1fixed in 0.3.30 | High7.1 | 0.3.30 |
| May 8 | LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists CVE-2026-44843High8.2fixed in 0.3.85, 1.3.3 | High8.2 | 0.3.85, 1.3.3 |
| Apr 8 | LangChain has incomplete f-string validation in prompt templates CVE-2026-40087Medium5.3fixed in 0.3.84, 1.2.28 | Medium5.3 | 0.3.84, 1.2.28 |
| Mar 27 | LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions CVE-2026-34070High7.5fixed in 1.2.22 | High7.5 | 1.2.22 |
| Feb 25 | LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader CVE-2026-27795Medium4.1fixed in 1.1.18 | Medium4.1 | 1.1.18 |
| Feb 11 | @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation CVE-2026-26019Medium4.1fixed in 1.1.14 | Medium4.1 | 1.1.14 |
| Feb 11 | LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages CVE-2026-26013Low3.7fixed in 1.2.11 | Low3.7 | 1.2.11 |
| Dec 232025 | LangChain serialization injection vulnerability enables secret extraction CVE-2025-68665High8.6fixed in 0.3.37, 0.3.80, 1.1.8, 1.2.3 | High8.6 | 0.3.37, 0.3.80, 1.1.8, 1.2.3 |
| Dec 232025 | LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs CVE-2025-68664Critical9.3fixed in 0.3.81, 1.2.5 | Critical9.3 | 0.3.81, 1.2.5 |
| Nov 202025 | LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates CVE-2025-65106Highfixed in 0.3.80, 1.0.7 | High | 0.3.80, 1.0.7 |
| Sep 42025 | Langchain Community Vulnerable to XML External Entity (XXE) Attacks CVE-2025-6984High7.5fixed in 0.3.27 | High7.5 | 0.3.27 |
| Jun 232025 | LangChain Community SSRF vulnerability exists in RequestsToolkit component CVE-2025-2828High8.4fixed in 0.0.28 | High8.4 | 0.0.28 |
| Mar 202025 | langchain-core allows unauthorized users to read arbitrary files from the host file system CVE-2024-10940Medium5.3fixed in 0.1.53, 0.2.43, 0.3.15 | Medium5.3 | 0.1.53, 0.2.43, 0.3.15 |
| Oct 292024 | Langchain SQL Injection vulnerability CVE-2024-8309Low4.9fixed in 0.2.0, 0.2.19 | Low4.9 | 0.2.0, 0.2.19 |
| Oct 292024 | @langchain/community SQL Injection vulnerability CVE-2024-7042Low4.9fixed in 0.3.3 | Low4.9 | 0.3.3 |
| Oct 292024 | Langchain Path Traversal vulnerability CVE-2024-7774Medium6.5fixed in 0.2.19 | Medium6.5 | 0.2.19 |
| Sep 192024 | LangChain Experimental Eval Injection vulnerability CVE-2024-46946Critical9.8no fix yet | Critical9.8 | No fix yet |
| Sep 172024 | LangChain pickle deserialization of untrusted data CVE-2024-5998High5.2fixed in 0.2.4 | High5.2 | 0.2.4 |
| Jul 152024 | langchain-experimental vulnerable to Arbitrary Code Execution CVE-2024-21513Critical8.5fixed in 0.0.21 | Critical8.5 | 0.0.21 |
| Jun 162024 | langchain_experimental Code Execution via Python REPL access CVE-2024-38459High7.8fixed in 0.0.61 | High7.8 | 0.0.61 |
| Jun 62024 | Denial of service in langchain-community CVE-2024-2965Medium4.2fixed in 0.2.5 | Medium4.2 | 0.2.5 |
| Jun 62024 | Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever CVE-2024-3095Medium4.8fixed in 0.2.9 | Medium4.8 | 0.2.9 |
| Apr 162024 | langchain vulnerable to path traversal CVE-2024-3571Medium6.5fixed in 0.0.353 | Medium6.5 | 0.0.353 |
| Mar 262024 | LangChain's XMLOutputParser vulnerable to XML Entity Expansion CVE-2024-1455Medium5.9fixed in 0.1.35 | Medium5.9 | 0.1.35 |
| Mar 42024 | LangChain directory traversal vulnerability CVE-2024-28088Lowfixed in 0.0.339, 0.1.30 | Low | 0.0.339, 0.1.30 |
| Mar 12024 | A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It CVE-2024-2057Critical9.8no fix yet | Critical9.8 | No fix yet |
| Feb 262024 | LangChain Experimental vulnerable to arbitrary code execution CVE-2024-27444Critical9.8fixed in 0.0.52 | Critical9.8 | 0.0.52 |
| Feb 262024 | langchain Server-Side Request Forgery vulnerability CVE-2024-0243Low3.7fixed in 0.1.0 | Low3.7 | 0.1.0 |
| Oct 212023 | Langchain Server-Side Request Forgery vulnerability CVE-2023-32786High7.5fixed in 0.0.329 | High7.5 | 0.0.329 |
| Oct 212023 | Langchain SQL Injection vulnerability CVE-2023-32785Critical9.8fixed in 0.0.247 | Critical9.8 | 0.0.247 |
| Oct 192023 | LangChain Server Side Request Forgery vulnerability CVE-2023-46229High8.8fixed in 0.0.317 | High8.8 | 0.0.317 |
| Oct 92023 | langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method CVE-2023-44467Critical9.8no fix yet | Critical9.8 | No fix yet |
| Sep 12023 | Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library CVE-2023-39631Critical9.8fixed in 0.0.308 | Critical9.8 | 0.0.308 |
| Aug 222023 | langchain vulnerable to arbitrary code execution CVE-2023-36281Critical9.8fixed in 0.0.312 | Critical9.8 | 0.0.312 |
| Aug 152023 | LangChain vulnerable to arbitrary code execution CVE-2023-38896Critical9.8fixed in 0.0.236 | Critical9.8 | 0.0.236 |
| Aug 152023 | LangChain vulnerable to arbitrary code execution CVE-2023-38860Critical9.8fixed in 0.0.247 | Critical9.8 | 0.0.247 |
| Aug 152023 | LangChain vulnerable to arbitrary code execution CVE-2023-39659Critical9.8fixed in 0.0.325 | Critical9.8 | 0.0.325 |
| Aug 52023 | langchain Code Injection vulnerability CVE-2023-36095Critical9.8fixed in 0.0.236 | Critical9.8 | 0.0.236 |
| Jul 62023 | langchain vulnerable to arbitrary code execution CVE-2023-36188Critical9.8fixed in 0.0.247 | Critical9.8 | 0.0.247 |
| Jul 62023 | langchain SQL Injection vulnerability CVE-2023-36189High7.5fixed in 0.0.247 | High7.5 | 0.0.247 |
| Jul 32023 | langchain arbitrary code execution vulnerability CVE-2023-36258Critical9.8fixed in 0.0.247 | Critical9.8 | 0.0.247 |
| Jun 202023 | Langchain vulnerable to arbitrary code execution CVE-2023-34541Critical9.8fixed in 0.0.247 | Critical9.8 | 0.0.247 |
| Jun 142023 | Langchain OS Command Injection vulnerability CVE-2023-34540Critical9.8fixed in 0.0.225 | Critical9.8 | 0.0.225 |
| Apr 52023 | LangChain vulnerable to code injection CVE-2023-29374Critical9.8no fix yet | Critical9.8 | No fix yet |