{"data":{"id":"07d4ff62-7a0c-4fac-8174-051a9b667a82","title":"GHSA-g28h-2cmm-rj9x: langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs","summary":"The `langchain-nvidia-ai-endpoints` library (a tool for connecting language models to NVIDIA's AI services) before version 1.4.2 had a local file disclosure vulnerability where attackers could trick the software into reading files from the computer's filesystem by providing malicious image inputs to Vision Language Model (VLM, an AI that processes images and text) requests. If an application let untrusted users control which images to process, attackers could access any files the application could read.","solution":"Upgrade to `langchain-nvidia-ai-endpoints >= 1.4.2`. The patched version rejects raw local filesystem paths for VLM image inputs and only accepts remote URLs, `data:image/...;base64,...` URIs (inline image data), and supported asset/file IDs. If immediate upgrade is not possible, reject local filesystem paths in user-controlled VLM image inputs and only allow trusted remote URLs, data URIs, or known safe asset/file IDs. Additionally, run applications with least-privilege filesystem access so the application process cannot read files it does not need.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-g28h-2cmm-rj9x","publishedAt":"2026-09-24T19:25:36.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["langchain-nvidia-ai-endpoints@<= 1.4.1 (fixed: 1.4.2)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["langchain-nvidia-ai-endpoints","NVIDIA","ChatNVIDIA","NVIDIARerank"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":true,"disclosureDate":"2026-09-24T19:25:36.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}