Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97869— langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserialization

Quick assessment

Affected
n/a langchain4j
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 langchain4j 1.5.3-beta10、1.11.10-beta18 以及 1.18.1-beta27 及更早版本中发现了一个缺陷。该漏洞影响 LangChain4j-agentic 组件中的 AgenticScopeJsonSerializationIT.java 文件里的 AgenticScopeSerializer.fromJson 函数。此问题会导致反序列化行为。远程利用该漏洞是可能的,但攻击复杂度被评定为高,且 exploits 的实际利用难度较大。目前已有公开的漏洞利用代码,可能被攻击者使

CVSS 4.1 · Medium EPSS 0.38% · P29
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97869

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
langchain4j LangChain4j-agentic AgenticScopeJsonSerializationIT.java AgenticScopeSerializer.fromJson deserialization
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-agentic. This manipulation causes deserialization. Remote exploitation of the attack is possible. The attack's complexity is rated as high. It is stated that the exploitability is difficult. The exploit has been published and may be used. Upgrading to version 1.5.3-beta11, 1.11.10-beta19 and 1.18.1-beta28 is able to resolve this issue. Upgrading the affected component is advised. The project maintainer kindly explains: "The issue was reported to us privately on 23 July 2026 and fixed in releases published on 29 July 2026. It is tracked as GHSA-gmwr-7wmf-mrjm. Exploitation requires an application to have enabled AgenticScope persistence, which is opt-in, and an attacker who can already write to that store. All maintained release lines have been patched."
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
可信数据的反序列化
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- langchain4j 1.5.3-beta10 cpe:2.3:a:langchain4j:langchain4j:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-97869

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97869

请登录查看更多情报信息。

Other References for CVE-2026-97869 (8)

Same Patch Batch · n/a · 2026-09-25 · 11 CVEs total

CVE-2026-52622 7.5 HIGH Wellav WES终端多个版本信息泄露漏洞
CVE-2026-97865 7.3 HIGH Open-Web-Analytics Remote Event Queue Endpoint queue.php loadFromArray deserialization
CVE-2026-88420 APSL puput v1.2.1-v2.2.0反射型XSS漏洞
CVE-2026-88389 Espruino 2v29空指针解引用致DoS
CVE-2026-88421 APSL puput 1.2.1-2.2.0 访问控制漏洞
CVE-2026-51772 OpenStack Glance v2 SSRF漏洞
CVE-2026-51773 OpenStack glance_store datastore驱动认证绕过漏洞
CVE-2026-78902 Netgate pfSense 26.03.1 pfBlockerNG跨站脚本漏洞
CVE-2026-79153 Seclore FileSecure Desktop Client <3.25.1.0 访问控制漏洞
CVE-2025-51457 D-Link DAP-2610<2.06B08r099命令注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-97869

No comments yet


Leave a comment