Skip to content

LangChain security advisories

45 advisories · 6 critical or high in 12 months · latest Jun 16

45 advisories

DateAdvisory
Jun 16LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-55443Medium5.1fixed in 1.3.9
May 13LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-45134High7.1fixed in 0.3.30
May 8LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-44843High8.2fixed in 0.3.85, 1.3.3
Apr 8LangChain has incomplete f-string validation in prompt templates
CVE-2026-40087Medium5.3fixed in 0.3.84, 1.2.28
Mar 27LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
CVE-2026-34070High7.5fixed in 1.2.22
Feb 25LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
CVE-2026-27795Medium4.1fixed in 1.1.18
Feb 11@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation
CVE-2026-26019Medium4.1fixed in 1.1.14
Feb 11LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2026-26013Low3.7fixed in 1.2.11
Dec 232025LangChain serialization injection vulnerability enables secret extraction
CVE-2025-68665High8.6fixed in 0.3.37, 0.3.80, 1.1.8, 1.2.3
Dec 232025LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
CVE-2025-68664Critical9.3fixed in 0.3.81, 1.2.5
Nov 202025LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
CVE-2025-65106Highfixed in 0.3.80, 1.0.7
Sep 42025Langchain Community Vulnerable to XML External Entity (XXE) Attacks
CVE-2025-6984High7.5fixed in 0.3.27
Jun 232025LangChain Community SSRF vulnerability exists in RequestsToolkit component
CVE-2025-2828High8.4fixed in 0.0.28
Mar 202025langchain-core allows unauthorized users to read arbitrary files from the host file system
CVE-2024-10940Medium5.3fixed in 0.1.53, 0.2.43, 0.3.15
Oct 292024Langchain SQL Injection vulnerability
CVE-2024-8309Low4.9fixed in 0.2.0, 0.2.19
Oct 292024@langchain/community SQL Injection vulnerability
CVE-2024-7042Low4.9fixed in 0.3.3
Oct 292024Langchain Path Traversal vulnerability
CVE-2024-7774Medium6.5fixed in 0.2.19
Sep 192024LangChain Experimental Eval Injection vulnerability
CVE-2024-46946Critical9.8no fix yet
Sep 172024LangChain pickle deserialization of untrusted data
CVE-2024-5998High5.2fixed in 0.2.4
Jul 152024langchain-experimental vulnerable to Arbitrary Code Execution
CVE-2024-21513Critical8.5fixed in 0.0.21
Jun 162024langchain_experimental Code Execution via Python REPL access
CVE-2024-38459High7.8fixed in 0.0.61
Jun 62024Denial of service in langchain-community
CVE-2024-2965Medium4.2fixed in 0.2.5
Jun 62024Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
CVE-2024-3095Medium4.8fixed in 0.2.9
Apr 162024langchain vulnerable to path traversal
CVE-2024-3571Medium6.5fixed in 0.0.353
Mar 262024LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CVE-2024-1455Medium5.9fixed in 0.1.35
Mar 42024LangChain directory traversal vulnerability
CVE-2024-28088Lowfixed in 0.0.339, 0.1.30
Mar 12024A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It
CVE-2024-2057Critical9.8no fix yet
Feb 262024LangChain Experimental vulnerable to arbitrary code execution
CVE-2024-27444Critical9.8fixed in 0.0.52
Feb 262024langchain Server-Side Request Forgery vulnerability
CVE-2024-0243Low3.7fixed in 0.1.0
Oct 212023Langchain Server-Side Request Forgery vulnerability
CVE-2023-32786High7.5fixed in 0.0.329
Oct 212023Langchain SQL Injection vulnerability
CVE-2023-32785Critical9.8fixed in 0.0.247
Oct 192023LangChain Server Side Request Forgery vulnerability
CVE-2023-46229High8.8fixed in 0.0.317
Oct 92023langchain_experimental vulnerable to arbitrary code execution via PALChain in the python exec method
CVE-2023-44467Critical9.8no fix yet
Sep 12023Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
CVE-2023-39631Critical9.8fixed in 0.0.308
Aug 222023langchain vulnerable to arbitrary code execution
CVE-2023-36281Critical9.8fixed in 0.0.312
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-38896Critical9.8fixed in 0.0.236
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-38860Critical9.8fixed in 0.0.247
Aug 152023LangChain vulnerable to arbitrary code execution
CVE-2023-39659Critical9.8fixed in 0.0.325
Aug 52023langchain Code Injection vulnerability
CVE-2023-36095Critical9.8fixed in 0.0.236
Jul 62023langchain vulnerable to arbitrary code execution
CVE-2023-36188Critical9.8fixed in 0.0.247
Jul 62023langchain SQL Injection vulnerability
CVE-2023-36189High7.5fixed in 0.0.247
Jul 32023langchain arbitrary code execution vulnerability
CVE-2023-36258Critical9.8fixed in 0.0.247
Jun 202023Langchain vulnerable to arbitrary code execution
CVE-2023-34541Critical9.8fixed in 0.0.247
Jun 142023Langchain OS Command Injection vulnerability
CVE-2023-34540Critical9.8fixed in 0.0.225
Apr 52023LangChain vulnerable to code injection
CVE-2023-29374Critical9.8no fix yet
About LangChain

The framework for LLM apps and agents, in Python and JavaScript.

Packages watched: langchain (PyPI), langchain-core (PyPI), langchain-community (PyPI), langchain-experimental (PyPI), langchain (npm), @langchain/core (npm), @langchain/community (npm).

LangChain elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.