LangChain LangGraph是LangChain公司开源的一个大模型框架。 LangChain LangGraph 3.1.1之前版本存在安全漏洞,该漏洞源于命名空间以点连接字符串持久化并以简单前缀模式匹配作用域读取,可能导致经过身份验证的调用者检索到属于其他租户或用户的项目。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| langchain-ai | langgraph | < 3.1.1 |
affected |
| langchain-ai | langgraph-checkpoint-postgres | < 3.1.1 |
affected |
| langchain-ai | langgraph-checkpoint-sqlite | < 3.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langchain-ai | langgraph | < 3.1.1 | - |
|
| langchain-ai | langgraph-checkpoint-sqlite | < 3.1.1 | - |
|
| langchain-ai | langgraph-checkpoint-postgres | < 3.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet