Catalog / LangChain

LangChain security advisories

All 9 advisories LangChain has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
99 carry a CVE
critical
1
high
3
medium
3
low
2
Fix in the archive
2of 9 matched to a release
Oldest
19 Nov 20259 months ago

7 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-55443medium

Path traversal and sandbox escape in LangChain file-search middleware and loaders

GHSA-gr75-jv2w-4656Fixed in 1.3.9
CVE-2026-44843high

Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists

GHSA-pjwx-r37v-7724Fixed in 1.3.3
CVE-2026-41481medium

HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

GHSA-fv5p-p927-qmxrFixed in 1.1.2, not held here
CVE-2026-41488low

Image token counting SSRF protection can be bypassed via DNS rebinding

GHSA-r7w7-9xr2-qq2rFixed in 1.1.14, not held here
CVE-2026-40087medium

Incomplete f-string validation in prompt templates

GHSA-926x-3r5x-gfhwFixed in 0.3.84, not held here
CVE-2026-34070high

Path traversal in legacy `load_prompt` functions in `langchain-core` (CWE-22)

GHSA-qh6h-p6c9-ff54Fixed in 1.2.22, not held here
CVE-2026-26013low

SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

GHSA-2g6r-c272-w58r
CVE-2025-68664critical

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

GHSA-c67j-w6g6-q2cmFixed in 1.2.5, not held here
CVE-2025-65106high

Template Injection via Attribute Access in Prompt Templates

GHSA-6qv9-48xg-fc7fFixed in 1.0.7, not held here