Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

langchain-ai — Vulnerabilities & Security Advisories 47

Browse all 47 CVE security advisories affecting langchain-ai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Langchain-ai provides a framework for developing applications powered by large language models, primarily facilitating the integration of external data sources and tools into AI workflows. Its architecture, which often involves dynamic code execution and complex dependency management, has historically exposed users to significant risks. Security audits reveal thirty-four recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, arbitrary file reads, and injection flaws. These vulnerabilities frequently stem from insufficient input validation in prompt templates and unsafe handling of untrusted data within chains. Notable incidents include critical flaws allowing attackers to execute arbitrary commands on host systems through manipulated LLM outputs or malicious tool definitions. The project’s reliance on third-party libraries and its flexible, often opaque, execution paths have contributed to a high vulnerability surface. Users must rigorously sanitize inputs and isolate execution environments to mitigate these inherent risks associated with dynamic AI application development.

CVE ID Title CVSS Severity Published
CVE-2026-55253 LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure — langchain-mongodb CWE-943 7.7 High 2026-09-14
CVE-2026-55235 langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication — langgraph-api CWE-287 5.9 Medium 2026-09-14
CVE-2026-55236 langgraph-api: Incomplete assistant authorization in LangGraph Server run creation — langgraph-api CWE-285 5.9 Medium 2026-09-14
CVE-2026-72848 langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitemap Index Entries, Allowing Server-Side Request Forgery — langchain-community CWE-918 8.6 High 2026-08-20
CVE-2026-71433 LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores — langgraph CWE-200 5.3 Medium 2026-08-06
CVE-2026-48121 @langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allows cross-tenant state access — langgraphjs CWE-943 6.7 Medium 2026-08-04
CVE-2026-59152 Arbitrary server-side file read in LangSmith SDK TracingMiddleware — langsmith-sdk CWE-22 5.0 Medium 2026-07-06
CVE-2026-14742 langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash — langgraph CWE-328 3.1 Low 2026-07-05
CVE-2026-55443 LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders — langchain CWE-22 5.1 Medium 2026-06-22
CVE-2026-48776 LangGraph SDK has unsafe URL path construction — langchain-ai CWE-22 4.2 Medium 2026-06-16
CVE-2026-48775 LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading — langgraph CWE-502 6.8 Medium 2026-06-16
CVE-2026-45134 LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning — langsmith-sdk CWE-502 7.1 High 2026-05-27
CVE-2026-44843 LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists — langchain CWE-502 8.2 High 2026-05-26
CVE-2026-41488 angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding — langchain-openai CWE-918 3.1 Low 2026-04-24
CVE-2026-41481 LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass — langchain-text-splitters CWE-918 6.5 Medium 2026-04-24
CVE-2026-41182 LangSmith SDK: Streaming token events bypass output redaction — langsmith-sdk CWE-200 5.3 Medium 2026-04-23
CVE-2026-40190 LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()` — langsmith-sdk CWE-1321 5.6 Medium 2026-04-10
CVE-2026-40087 LangChain has incomplete f-string validation in prompt templates — langchain CWE-1336 5.3 Medium 2026-04-09
CVE-2026-34070 LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions — langchain CWE-22 7.5 High 2026-03-31
CVE-2026-28277 LangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading — langgraph CWE-502 6.8 Medium 2026-03-05
CVE-2026-25750 LangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via Malicious baseUrl — helm CWE-74 8.9AI High AI 2026-03-04
CVE-2026-27795 LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader — langchainjs CWE-918 4.1 Medium 2026-02-25
CVE-2026-27794 LangGraph: BaseCache Deserialization of Untrusted Data may lead to Remote Code Execution — langgraph-checkpoint CWE-502 6.6 Medium 2026-02-25
CVE-2026-27022 RediSearch Query Injection in @langchain/langgraph-checkpoint-redis — langgraphjs CWE-74 6.5 Medium 2026-02-20
CVE-2026-26019 @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation — langchainjs CWE-918 4.1 Medium 2026-02-11
CVE-2026-26013 LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages — langchain CWE-918 3.7 Low 2026-02-10
CVE-2026-25528 LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection — langsmith-sdk CWE-918 5.8 Medium 2026-02-09
CVE-2025-68665 LangChain serialization injection vulnerability enables secret extraction — langchainjs CWE-502 8.6 High 2025-12-23
CVE-2025-68664 LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs — langchain CWE-502 9.3 Critical 2025-12-23
CVE-2025-67644 LangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer list method — langgraph CWE-89 7.3 High 2025-12-10

This page lists every published CVE security advisory associated with langchain-ai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.