Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.5
CVE-2026-55443
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths…
Langchain
1.3.9+
CRITICAL 9.1
CVE-2026-48776
LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs from Python applications. Versio…
Langgraph Sdk
0.3.15+
MEDIUM 6.8
CVE-2026-48775
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4…
Langgraph Checkpoint
4.1.1+
HIGH 8.2
CVE-2026-44843
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths tha…
Langchain
0.3.85 / 1.3.3+
MEDIUM 6.5
CVE-2026-41481
LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters
1.1.2, HTMLHeaderTextSplitter.split_tex…
Langchain Text Splitters
1.1.2+
CRITICAL 9.8
CVE-2026-40190
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith)…
Langsmith
0.5.18+
MEDIUM 5.3
CVE-2026-40087
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validatio…
Langchain Core
0.3.84 / 1.2.28+
HIGH 7.5
CVE-2026-34070
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.load…
Langchain Core
1.2.22+
HIGH 7.2
CVE-2026-28277
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.…
Langgraph
after 1.0.9
HIGH 8.1
CVE-2026-25750
Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter…
Langsmith
0.12.71+
HIGH 7.4
CVE-2026-27795
LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass ex…
Langchain Community
1.1.18+
HIGH 7.5
CVE-2024-58340
LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() met…
Langchain
after 0.3.1
CRITICAL 9.1
CVE-2025-68665
LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0…
Langchain.js
0.3.37 / 0.3.80+
HIGH 8.2
CVE-2025-68664EPSS 42%
LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerabilit…
Langchain Core
0.3.81 / 1.2.5+
HIGH 7.8
CVE-2025-67644
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.…
Langgraph Checkpoint Sqlite
3.0.1+
CRITICAL 10.0
CVE-2025-2828EPSS 16%
A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchai…
Langchain
0.0.28+
CRITICAL 9.8
CVE-2024-8309EPSS 14%
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulne…
Langchain
Patch available
CRITICAL 9.1
CVE-2024-7774
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to s…
Langchain.js
Patch available
CRITICAL 9.8
CVE-2024-7042
A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injecti…
Langchain
0.3.1+
CRITICAL 9.8
CVE-2024-46946
langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympi…
Langchain Experimental
after 0.3.0
HIGH 7.8
CVE-2024-5998
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can …
Langchain
0.2.9+
HIGH 8.5
CVE-2024-21513
Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from t…
Langchain Experimental
0.0.21+
HIGH 7.8
CVE-2024-38459
langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue …
Langchain Experimental
0.0.61+
HIGH 7.7
CVE-2024-3095
A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulner…
Langchain
0.2.9+
HIGH 8.8
CVE-2024-3571
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its L…
Langchain
Patch available
MEDIUM 5.9
CVE-2024-1455
A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nes…
Langchain
after 0.1.35
HIGH 8.1
CVE-2024-28088
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call.…
Langchain
0.1.12+
CRITICAL 9.8
CVE-2024-2057
A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the lib…
Langchain
Patch available
CRITICAL 9.8
CVE-2024-27444
langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitra…
Langchain Experimental
0.1.8+
HIGH 8.1
CVE-2024-0243
With the following crawler configuration:
```python
from bs4 import BeautifulSoup as Soup
url = "https://example.com"
loader = RecursiveUrlLoader(
…
Langchain
0.1.0+