Where
-Infinity
0

pypi/langchainLangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

Risk 32
Severity
5.5
First published (updated )

pypi/langgraphLangGraph SDK has unsafe URL path construction

Risk 66
Severity
9.1
First published (updated )

pypi/langgraphLangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

Risk 62
Severity
6.8
First published (updated )

pip/langchain-coreLangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists

Risk 58
Severity
8.2
First published (updated )

pypi/langchain-openaiangchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

Risk 17
Severity
3.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/langchain-text-splittersLangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

Risk 37
Severity
6.5
First published (updated )

npm/langsmithLangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`

Risk 86
Severity
9.8
First published (updated )

IBM Engineering AI HubLangChain has incomplete f-string validation in prompt templates

Risk 27
Severity
5.3
First published (updated )

IBM Engineering AI HubLangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions

Risk 43
Severity
7.5
First published (updated )

pypi/langgraphLangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading

Risk 49
Severity
7.2
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

helm/langchain-ai/helmLangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via Malicious baseUrl

Risk 64
Severity
8.5
First published (updated )

npm/@langchain/communityLangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader

Risk 30
Severity
7.4
EPSS
0.03%
First published (updated )

npm/@langchain/community@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation

Risk 16
Severity
4.1
EPSS
0.01%
First published (updated )

pypi/langchainLangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

Risk 15
Severity
3.7
EPSS
0.01%
First published (updated )

pypi/langchainLangChain <= 0.3.1 MRKLOutputParser ReDoS

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/langchainLangChain serialization injection vulnerability enables secret extraction

Risk 66
Severity
9.1
First published (updated )

pip/langchain-coreLangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

Risk 70
Severity
9.3
First published (updated )

pip/langgraph-checkpoint-sqliteLangGraph SQLite Checkpoint is vulnerable to SQL Injection via metadata filter key in checkpointer list method

Risk 69
Severity
7.8
First published (updated )

Langchain langgraph-checkpoint-sqliteSQL Injection in langchain-ai/langchain

Risk 47
Severity
7.3
First published (updated )

Langchain langchain-text-splittersXXE Vulnerability in langchain-ai/langchain

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Langchain ChatGLM-WebuiInsecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view an…

Risk 86
Severity
9.8
First published (updated )

Langchain langchain-aiCode Injection

Risk 86
Severity
9.8
First published (updated )

langchain-ai langchainSSRF Vulnerability in RequestsToolkit in langchain-ai/langchain

Risk 91
Severity
10
First published (updated )

pip/langchain-communitySQL Injection in langchain-ai/langchain

Risk 89
Severity
9.8
First published (updated )

npm/@langchain/communityPrompt Injection in langchain-ai/langchainjs Leading to SQL Injection

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/langchainPath Traversal in langchain-ai/langchainjs

Risk 69
Severity
9.1
First published (updated )

pip/langchain-experimentalInput Validation

Risk 89
Severity
9.8
First published (updated )

pip/langchain-communityDeserialization of Untrusted Data in langchain-ai/langchain

Risk 71
Severity
7.8
First published (updated )

pip/langchain-experimentalCode Injection

Risk 76
Severity
8.6
First published (updated )

pip/langchain-experimentallangchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL…

Risk 71
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203