Please use LangChain VDP and LangChain Open Source VDP to report security vulnerabilities.
Security: langchain-ai/langchain
Security
SECURITY.md
-
Path traversal and sandbox escape in LangChain file-search middleware and loadersGHSA-gr75-jv2w-4656 published
Jun 12, 2026 by nick-hollon-lcModerate -
Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlistsGHSA-pjwx-r37v-7724 published
May 5, 2026 by eyurtsevHigh -
Image token counting SSRF protection can be bypassed via DNS rebindingGHSA-r7w7-9xr2-qq2r published
Apr 16, 2026 by ccurmeLow -
Incomplete f-string validation in prompt templatesGHSA-926x-3r5x-gfhw published
Apr 8, 2026 by eyurtsevModerate -
Path traversal in legacy `load_prompt` functions in `langchain-core` (CWE-22)GHSA-qh6h-p6c9-ff54 published
Mar 26, 2026 by ccurmeHigh -
HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect BypassGHSA-fv5p-p927-qmxr published
Apr 16, 2026 by ccurmeModerate -
SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messagesGHSA-2g6r-c272-w58r published
Feb 10, 2026 by ccurmeLow -
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIsGHSA-c67j-w6g6-q2cm published
Dec 23, 2025 by eyurtsevCritical -
Template Injection via Attribute Access in Prompt TemplatesGHSA-6qv9-48xg-fc7f published
Nov 19, 2025 by eyurtsevHigh
Learn more about advisories related to langchain-ai/langchain in the GitHub Advisory Database