langchain
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 49 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 5, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding
LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
LangChain has incomplete f-string validation in prompt templates
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
LangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading
LangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via Malicious baseUrl
LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Monitor langchain in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.