LangChain
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 53 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 5, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangGraph SDK has unsafe URL path construction
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
LangChain has incomplete f-string validation in prompt templates
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
LangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading
Monitor LangChain in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.