LangChain langgraph是LangChain公司开源的一个大模型框架。 LangChain langgraph存在安全漏洞,该漏洞源于JsonPlusSerializer可以从JSON检查点有效载荷重构Python对象,导致反序列化路径重构超出应用程序预期的对象,从而在检查点加载时可能导致代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| langchain-ai | langgraph | < 1.2.2 |
affected |
| langchain-ai | langraph-checkpoint | < 4.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langchain-ai | langgraph | < 1.2.2 | - |
|
| langchain-ai | langraph-checkpoint | < 4.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet