Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Langchain MEDIUM 5.5
CVE-2026-55443

LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths…

Fix: 1.3.9+
Fix from $1,600 2026-06-22
Langgraph Sdk CRITICAL 9.1
CVE-2026-48776

LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versio…

Fix: 0.3.15+
Fix from $2,300 2026-06-17
Langgraph Checkpoint MEDIUM 6.8
CVE-2026-48775

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4…

Fix: 4.1.1+
Fix from $1,600 2026-06-16
Langchain HIGH 8.2
CVE-2026-44843

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths tha…

Fix: 0.3.85 / 1.3.3+
Fix from $1,950 2026-05-26
Langchain Text Splitters MEDIUM 6.5
CVE-2026-41481

LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHeaderTextSplitter.split_tex…

Fix: 1.1.2+
Fix from $1,600 2026-04-24
Langsmith CRITICAL 9.8
CVE-2026-40190

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith)…

Fix: 0.5.18+
Fix from $2,300 2026-04-10
Langchain Core MEDIUM 5.3
CVE-2026-40087

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validatio…

Fix: 0.3.84 / 1.2.28+
Fix from $1,600 2026-04-09
Langchain Core HIGH 7.5
CVE-2026-34070

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.load…

Fix: 1.2.22+
Fix from $1,950 2026-03-31
Langgraph HIGH 7.2
CVE-2026-28277

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.…

Fix: after 1.0.9
Fix from $1,950 2026-03-05
Langsmith HIGH 8.1
CVE-2026-25750

Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter…

Fix: 0.12.71+
Fix from $1,950 2026-03-04
Langchain Community HIGH 7.4
CVE-2026-27795

LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass ex…

Fix: 1.1.18+
Fix from $1,950 2026-02-25
Langchain HIGH 7.5
CVE-2024-58340

LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() met…

Fix: after 0.3.1
Fix from $1,950 2026-01-12
Langchain.js CRITICAL 9.1
CVE-2025-68665

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0…

Fix: 0.3.37 / 0.3.80+
Fix from $2,300 2025-12-23
Langchain Core HIGH 8.2
CVE-2025-68664EPSS 42%

LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerabilit…

Fix: 0.3.81 / 1.2.5+
Fix from $1,950 2025-12-23
Langgraph Checkpoint Sqlite HIGH 7.8
CVE-2025-67644

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.…

Fix: 3.0.1+
Fix from $1,950 2025-12-11
Langchain CRITICAL 10.0
CVE-2025-2828EPSS 16%

A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai…

Fix: 0.0.28+
Fix from $2,300 2025-06-23
Langchain CRITICAL 9.8
CVE-2024-8309EPSS 14%

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulne…

Patch available
Fix from $2,300 2024-10-29
Langchain.js CRITICAL 9.1
CVE-2024-7774

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to s…

Patch available
Fix from $2,300 2024-10-29
Langchain CRITICAL 9.8
CVE-2024-7042

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injecti…

Fix: 0.3.1+
Fix from $2,300 2024-10-29
Langchain Experimental CRITICAL 9.8
CVE-2024-46946

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympi…

Fix: after 0.3.0
Fix from $2,300 2024-09-19
Langchain HIGH 7.8
CVE-2024-5998

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can …

Fix: 0.2.9+
Fix from $1,950 2024-09-17
Langchain Experimental HIGH 8.5
CVE-2024-21513

Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from t…

Fix: 0.0.21+
Fix from $1,950 2024-07-15
Langchain Experimental HIGH 7.8
CVE-2024-38459

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue …

Fix: 0.0.61+
Fix from $1,950 2024-06-16
Langchain HIGH 7.7
CVE-2024-3095

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulner…

Fix: 0.2.9+
Fix from $1,950 2024-06-06
Langchain HIGH 8.8
CVE-2024-3571

langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its L…

Patch available
Fix from $1,950 2024-04-16
Langchain MEDIUM 5.9
CVE-2024-1455

A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nes…

Fix: after 0.1.35
Fix from $1,600 2024-03-26
Langchain HIGH 8.1
CVE-2024-28088

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call.…

Fix: 0.1.12+
Fix from $1,950 2024-03-04
Langchain CRITICAL 9.8
CVE-2024-2057

A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the lib…

Patch available
Fix from $2,300 2024-03-01
Langchain Experimental CRITICAL 9.8
CVE-2024-27444

langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitra…

Fix: 0.1.8+
Fix from $2,300 2024-02-26
Langchain HIGH 8.1
CVE-2024-0243

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( …

Fix: 0.1.0+
Fix from $1,950 2024-02-26