langchain-ai
AI / MLoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting langchain-ai.
- CVE-2026-55253LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure7.7
- CVE-2026-55235langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication5.9
- CVE-2026-55236langgraph-api: Incomplete assistant authorization in LangGraph Server run creation5.9
- CVE-2026-72848langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitemap Index Entries, Allowing Server-Side Request Forgery8.6
- CVE-2026-71433LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores5.3
- CVE-2026-48121@langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allows cross-tenant state access6.7
- CVE-2026-59152Arbitrary server-side file read in LangSmith SDK TracingMiddleware5.0
- CVE-2026-14742langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash3.1
- CVE-2026-55443LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders5.1
- CVE-2026-48776LangGraph SDK has unsafe URL path construction4.2
- CVE-2026-48775LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading6.8
- CVE-2026-45134LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning7.1
- CVE-2026-44843LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists8.2
- CVE-2026-41488angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding3.1
- CVE-2026-41481LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass6.5