Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain security advisories
All 9 advisories LangChain has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 99 carry a CVE
- critical
- 1
- high
- 3
- medium
- 3
- low
- 2
- Fix in the archive
- 2of 9 matched to a release
- Oldest
- 19 Nov 20259 months ago
7 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productUnsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass
Image token counting SSRF protection can be bypassed via DNS rebinding
Incomplete f-string validation in prompt templates
Path traversal in legacy `load_prompt` functions in `langchain-core` (CWE-22)
SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Template Injection via Attribute Access in Prompt Templates