CVE-2025-6984: Sensitive Information Disclosure Due to Insecure XML Parsing in langchain-ai/langchain

Published Sep 4, 2025
·
Updated

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd.

Other sources

The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malicious XML payload that references local files, potentially exposing sensitive data such as /etc/passwd. This issue has been fixed in 0.3.27 of langchain-community.

GitHub

Affected Software

3 affected componentsFixes available
langchain-ai langchain
pip/langchain-community<0.3.27
0.3.27
IBM Concert Software<=1.0.0-2.1.0

Event History

Sep 4, 2025
CVE Published
via MITRE·08:07 AM
Data Sourced
via MITRE·08:07 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·09:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·10:42 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·12:30 PM
Data Sourced
via GitHub·12:30 PM
DescriptionSeverityWeaknessAffected Software
Feb 10, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-6984?

CVE-2025-6984 has a high severity rating due to its potential to lead to XML External Entity attacks.

2

How do I fix CVE-2025-6984?

To fix CVE-2025-6984, update the EverNoteLoader component to a version where external entity parsing is disabled.

3

What products are affected by CVE-2025-6984?

The langchain-ai/langchain project, specifically version 0.3.63 of the EverNoteLoader component, is affected by CVE-2025-6984.

4

How can CVE-2025-6984 be exploited?

CVE-2025-6984 can be exploited through malicious XML input that leverages external entity references.

5

What are the potential impacts of CVE-2025-6984?

The potential impacts of CVE-2025-6984 include data exposure and denial of service due to the improper handling of XML input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203