{"data":{"id":"bd892e03-a6e0-4e26-b8b4-7755753e19cc","title":"CVE-2026-97869: A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the fun","summary":"A vulnerability was found in langchain4j (a framework for building AI applications) up to versions 1.5.3-beta10, 1.11.10-beta18, and 1.18.1-beta27 in a function called AgenticScopeSerializer.fromJson that improperly handles deserialization (converting data back into objects, which can allow attackers to inject malicious code). Remote attackers could potentially exploit this, though it requires high complexity and the application must have a specific feature called AgenticScope persistence enabled.","solution":"Upgrade to version 1.5.3-beta11, 1.11.10-beta19, or 1.18.1-beta28, depending on which release line you are using.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-97869","publishedAt":"2026-09-25T16:17:31.740Z","cveId":"CVE-2026-97869","cweIds":["CWE-20","CWE-502"],"cvssScore":"4.1","cvssSeverity":"medium","severity":"medium","attackType":["model_poisoning"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["LangChain4j"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"high","privilegesRequired":"high","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-25T16:17:31.740Z","capecIds":["CAPEC-586"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}