Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

langchain-ai — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting langchain-ai. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Langchain-ai provides a framework for developing applications powered by large language models, primarily facilitating the integration of external data sources and tools into AI workflows. Its architecture, which often involves dynamic code execution and complex dependency management, has historically exposed users to significant risks. Security audits reveal thirty-four recorded Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, arbitrary file reads, and injection flaws. These vulnerabilities frequently stem from insufficient input validation in prompt templates and unsafe handling of untrusted data within chains. Notable incidents include critical flaws allowing attackers to execute arbitrary commands on host systems through manipulated LLM outputs or malicious tool definitions. The project’s reliance on third-party libraries and its flexible, often opaque, execution paths have contributed to a high vulnerability surface. Users must rigorously sanitize inputs and isolate execution environments to mitigate these inherent risks associated with dynamic AI application development.

Found 12 results / 48 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2025-8709 SQL Injection in langchain-ai/langchain — langchain-ai/langchain CWE-89 9.8 - 2025-10-26
CVE-2025-6985 XXE Vulnerability in langchain-ai/langchain — langchain-ai/langchain CWE-611 7.5AI High AI 2025-10-06
CVE-2025-6984 Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain — langchain-ai/langchain CWE-200 7.5 - 2025-09-04
CVE-2025-2828 SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain — langchain-ai/langchain CWE-918 7.5 - 2025-06-23
CVE-2024-10940 Exposure of Sensitive System Information via ImagePromptTemplate in langchain-ai/langchain — langchain-ai/langchain CWE-497 7.5 - 2025-03-20
CVE-2024-8309 SQL Injection in langchain-ai/langchain — langchain-ai/langchain CWE-89 9.8 - 2024-10-29
CVE-2024-5998 Deserialization of Untrusted Data in langchain-ai/langchain — langchain-ai/langchain CWE-502 9.8 - 2024-09-17
CVE-2024-2965 Denial-of-Service in LangChain SitemapLoader in langchain-ai/langchain — langchain-ai/langchain CWE-674 7.5AI High AI 2024-06-06
CVE-2024-3095 SSRF in Langchain Web Research Retriever in langchain-ai/langchain — langchain-ai/langchain CWE-918 9.1AI Critical AI 2024-06-06
CVE-2024-3571 Path Traversal in langchain-ai/langchain — langchain-ai/langchain CWE-22 9.8 - 2024-04-16
CVE-2024-1455 Billion Laughs Attack leading to DoS in langchain-ai/langchain — langchain-ai/langchain CWE-776 7.5AI High AI 2024-03-26
CVE-2024-0243 Server-side Request Forgery In Recursive URL Loader — langchain-ai/langchain CWE-918 9.3 - 2024-02-24

This page lists every published CVE security advisory associated with langchain-ai. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.