{"data":{"ecosystem":"pypi","name":"langchain","url":"https://aisecwatch.com/packages/pypi/langchain","latestVersion":"1.4.4","firstReleaseAt":"2022-10-25T04:10:02.367Z","repository":"https://github.com/langchain-ai/langchain","llm":{"exposure":"direct","depth":0,"integratedAt":"2022-10-25T04:10:02.367Z","integratedVersion":"0.0.1","sdks":["langchain"],"path":[]},"authority":{"profile":["mcp_tools"],"fromDependencies":["pypi:fastmcp"]},"dependencies":[{"ecosystem":"pypi","name":"fastmcp","versionSpec":"<5.0.0,>=4.0.11","scope":"extra:mcp"},{"ecosystem":"pypi","name":"langchain-anthropic","versionSpec":null,"scope":"extra:anthropic"},{"ecosystem":"pypi","name":"langchain-aws","versionSpec":null,"scope":"extra:aws"},{"ecosystem":"pypi","name":"langchain-azure-ai","versionSpec":null,"scope":"extra:azure-ai"},{"ecosystem":"pypi","name":"langchain-baseten","versionSpec":">=0.2.0","scope":"extra:baseten"},{"ecosystem":"pypi","name":"langchain-community","versionSpec":null,"scope":"extra:community"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2.0.0,>=1.6.9","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-deepseek","versionSpec":null,"scope":"extra:deepseek"},{"ecosystem":"pypi","name":"langchain-fireworks","versionSpec":null,"scope":"extra:fireworks"},{"ecosystem":"pypi","name":"langchain-google-genai","versionSpec":null,"scope":"extra:google-genai"},{"ecosystem":"pypi","name":"langchain-google-vertexai","versionSpec":null,"scope":"extra:google-vertexai"},{"ecosystem":"pypi","name":"langchain-groq","versionSpec":null,"scope":"extra:groq"},{"ecosystem":"pypi","name":"langchain-huggingface","versionSpec":null,"scope":"extra:huggingface"},{"ecosystem":"pypi","name":"langchain-meta","versionSpec":null,"scope":"extra:meta"},{"ecosystem":"pypi","name":"langchain-mistralai","versionSpec":null,"scope":"extra:mistralai"},{"ecosystem":"pypi","name":"langchain-ollama","versionSpec":null,"scope":"extra:ollama"},{"ecosystem":"pypi","name":"langchain-openai","versionSpec":null,"scope":"extra:openai"},{"ecosystem":"pypi","name":"langchain-perplexity","versionSpec":null,"scope":"extra:perplexity"},{"ecosystem":"pypi","name":"langchain-together","versionSpec":null,"scope":"extra:together"},{"ecosystem":"pypi","name":"langchain-xai","versionSpec":null,"scope":"extra:xai"},{"ecosystem":"pypi","name":"langgraph","versionSpec":"<1.3.0,>=1.2.11","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3.0.0,>=2.7.4","scope":"runtime"}],"advisories":[{"id":"91cf3a90-9e28-4efc-81cf-044cf29caebf","url":"https://aisecwatch.com/issues/91cf3a90-9e28-4efc-81cf-044cf29caebf","cveId":"CVE-2026-55443","title":"CVE-2026-55443: LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components…","headline":"LangChain path confinement flaws expose files outside intended root","severity":"medium","publishedAt":"2026-06-22T19:17:21.537Z","affected":["langchain@<= 1.3.8 (fixed: 1.3.9)","langchain-anthropic@<= 1.4.5 (fixed: 1.4.6)"],"epssScore":0.0021,"matchedBy":"ecosystem"},{"id":"1526169a-7130-4ea8-92d6-e2e854148727","url":"https://aisecwatch.com/issues/1526169a-7130-4ea8-92d6-e2e854148727","cveId":null,"title":"GHSA-gr75-jv2w-4656: LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","headline":null,"severity":"medium","publishedAt":"2026-06-16T15:03:14.000Z","affected":["langchain-anthropic@<= 1.4.5 (fixed: 1.4.6)","langchain@<= 1.3.8 (fixed: 1.3.9)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"51fb1fdb-be21-4f50-8ce9-9dcd9036cf68","url":"https://aisecwatch.com/issues/51fb1fdb-be21-4f50-8ce9-9dcd9036cf68","cveId":"CVE-2026-45134","title":"GHSA-3644-q5cj-c5c7: LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","headline":null,"severity":"high","publishedAt":"2026-05-13T15:29:30.000Z","affected":["langchain@< 0.3.30 (fixed: 0.3.30)","langchain-classic@< 1.0.7 (fixed: 1.0.7)","langsmith@< 0.6.0 (fixed: 0.6.0)","langsmith@< 0.8.0 (fixed: 0.8.0)"],"epssScore":0.00344,"matchedBy":"ecosystem"},{"id":"8b806c72-5762-4757-b287-3889235e009f","url":"https://aisecwatch.com/issues/8b806c72-5762-4757-b287-3889235e009f","cveId":"CVE-2024-8309","title":"CVE-2024-8309: A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection…","headline":"langchain GraphCypherQAChain SQL injection through prompt injection","severity":"critical","publishedAt":"2024-10-29T17:15:10.950Z","affected":["langchain@< 0.2.0 (fixed: 0.2.0)","langchain-community@>= 0.2.0, < 0.2.19 (fixed: 0.2.19)"],"epssScore":0.13738,"matchedBy":"ecosystem"},{"id":"782033d4-5b70-456e-a296-8286fec016eb","url":"https://aisecwatch.com/issues/782033d4-5b70-456e-a296-8286fec016eb","cveId":"CVE-2024-2965","title":"GHSA-3hjh-jh2h-vrg6: Denial of service in langchain-community","headline":null,"severity":"medium","publishedAt":"2024-06-06T21:30:36.000Z","affected":["langchain-community@< 0.2.5 (fixed: 0.2.5)","langchain@>= 0, < 0.2.5 (fixed: 0.2.5)"],"epssScore":0.00304,"matchedBy":"ecosystem"},{"id":"e08d52a1-f7a4-4deb-bf5d-be028cf95282","url":"https://aisecwatch.com/issues/e08d52a1-f7a4-4deb-bf5d-be028cf95282","cveId":"CVE-2024-3571","title":"CVE-2024-3571: langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted…","headline":"langchain-ai/langchain path traversal in LocalFileStore mset and mget methods","severity":"high","publishedAt":"2024-04-16T04:15:12.203Z","affected":["langchain@< 0.0.353 (fixed: 0.0.353)"],"epssScore":0.01871,"matchedBy":"ecosystem"},{"id":"07990f4e-8a0a-48ec-a8f1-06723a796686","url":"https://aisecwatch.com/issues/07990f4e-8a0a-48ec-a8f1-06723a796686","cveId":"CVE-2024-28088","title":"CVE-2024-28088: LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path…","headline":"LangChain directory traversal in load_chain path parameter","severity":"high","publishedAt":"2024-03-04T05:15:47.017Z","affected":["langchain@< 0.0.339 (fixed: 0.0.339)","langchain-core@>= 0, < 0.1.30 (fixed: 0.1.30)"],"epssScore":0.0174,"matchedBy":"ecosystem"},{"id":"7c404b6c-f1d6-4f96-a44e-51441c3403e1","url":"https://aisecwatch.com/issues/7c404b6c-f1d6-4f96-a44e-51441c3403e1","cveId":"CVE-2024-0243","title":"GHSA-h9j7-5xvc-qhg5: langchain Server-Side Request Forgery vulnerability","headline":null,"severity":"low","publishedAt":"2024-02-26T18:30:29.000Z","affected":["langchain@< 0.1.0 (fixed: 0.1.0)"],"epssScore":0.00517,"matchedBy":"ecosystem"},{"id":"c0d8d007-2814-4a1d-9bb8-f55c7df0e355","url":"https://aisecwatch.com/issues/c0d8d007-2814-4a1d-9bb8-f55c7df0e355","cveId":"CVE-2023-32786","title":"CVE-2023-32786: In Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an…","headline":"Langchain prompt injection enables SSRF via arbitrary URL retrieval","severity":"high","publishedAt":"2023-10-21T02:15:10.553Z","affected":["langchain@< 0.0.329 (fixed: 0.0.329)"],"epssScore":0.00699,"matchedBy":"ecosystem"},{"id":"3168406e-a5c6-497d-a4e8-ee5ead4afa3a","url":"https://aisecwatch.com/issues/3168406e-a5c6-497d-a4e8-ee5ead4afa3a","cveId":"CVE-2023-32785","title":"GHSA-8h5w-f6q9-wg35: Langchain SQL Injection vulnerability","headline":null,"severity":"critical","publishedAt":"2023-10-21T00:30:47.000Z","affected":["langchain@< 0.0.247 (fixed: 0.0.247)"],"epssScore":0,"matchedBy":"ecosystem"},{"id":"088ac727-32cb-4cb5-bb53-e165e5c661c7","url":"https://aisecwatch.com/issues/088ac727-32cb-4cb5-bb53-e165e5c661c7","cveId":"CVE-2023-46229","title":"CVE-2023-46229: LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an…","headline":"LangChain SSRF via recursive URL loader crawling to internal servers","severity":"high","publishedAt":"2023-10-19T09:15:58.737Z","affected":["langchain@>= 0, < 0.0.317 (fixed: 0.0.317)"],"epssScore":0.44711,"matchedBy":"ecosystem"},{"id":"a59d48d1-82c7-45b4-91a5-6813bdefea2a","url":"https://aisecwatch.com/issues/a59d48d1-82c7-45b4-91a5-6813bdefea2a","cveId":"CVE-2023-39631","title":"CVE-2023-39631: An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate…","headline":"LanChain-ai Langchain code execution through evaluate function","severity":"critical","publishedAt":"2023-09-01T20:15:08.370Z","affected":["langchain@< 0.0.308 (fixed: 0.0.308)","numexpr@< 2.8.5 (fixed: 2.8.5)"],"epssScore":0.016,"matchedBy":"ecosystem"},{"id":"236e6fa2-5f05-42dc-9e41-16ee52660210","url":"https://aisecwatch.com/issues/236e6fa2-5f05-42dc-9e41-16ee52660210","cveId":"CVE-2023-36281","title":"CVE-2023-36281: An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This…","headline":"langchain remote code execution through JSON file in load_prompt","severity":"critical","publishedAt":"2023-08-22T23:16:36.457Z","affected":["langchain@< 0.0.312 (fixed: 0.0.312)"],"epssScore":0.0344,"matchedBy":"ecosystem"},{"id":"e1058d3c-a146-482c-b2bf-25f847753384","url":"https://aisecwatch.com/issues/e1058d3c-a146-482c-b2bf-25f847753384","cveId":"CVE-2023-39659","title":"CVE-2023-39659: An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a…","headline":"langchain arbitrary code execution through PythonAstREPLTool._run","severity":"critical","publishedAt":"2023-08-15T21:15:12.930Z","affected":["langchain@< 0.0.325 (fixed: 0.0.325)"],"epssScore":0.01534,"matchedBy":"ecosystem"},{"id":"1f5b1182-320e-43fa-abaf-85092bbcbd13","url":"https://aisecwatch.com/issues/1f5b1182-320e-43fa-abaf-85092bbcbd13","cveId":"CVE-2023-38896","title":"CVE-2023-38896: An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the…","headline":null,"severity":"critical","publishedAt":"2023-08-15T21:15:12.027Z","affected":["langchain@< 0.0.236 (fixed: 0.0.236)"],"epssScore":0.01838,"matchedBy":"ecosystem"},{"id":"e79f8579-f3d7-4824-b15d-bbaee97c5ae9","url":"https://aisecwatch.com/issues/e79f8579-f3d7-4824-b15d-bbaee97c5ae9","cveId":"CVE-2023-38860","title":"CVE-2023-38860: An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.","headline":"LangChain arbitrary code execution via prompt parameter","severity":"critical","publishedAt":"2023-08-15T21:15:11.737Z","affected":["langchain@>= 0, < 0.0.247 (fixed: 0.0.247)"],"epssScore":0.01417,"matchedBy":"ecosystem"},{"id":"a308d573-66fb-4163-acf8-c507ff2ed7d3","url":"https://aisecwatch.com/issues/a308d573-66fb-4163-acf8-c507ff2ed7d3","cveId":"CVE-2023-36095","title":"CVE-2023-36095: An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls…","headline":"langchain arbitrary code execution through PALChain python exec calls","severity":"critical","publishedAt":"2023-08-05T07:15:13.580Z","affected":["langchain@< 0.0.236 (fixed: 0.0.236)"],"epssScore":0.0117,"matchedBy":"ecosystem"},{"id":"ef9ff595-1f9e-48a2-810a-021883ea413f","url":"https://aisecwatch.com/issues/ef9ff595-1f9e-48a2-810a-021883ea413f","cveId":"CVE-2023-36189","title":"CVE-2023-36189: SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via…","headline":"langchain SQL injection in SQLDatabaseChain component","severity":"high","publishedAt":"2023-07-06T18:15:10.707Z","affected":["langchain@>= 0, < 0.0.247 (fixed: 0.0.247)"],"epssScore":0.01248,"matchedBy":"ecosystem"},{"id":"6551f2fa-abb7-4573-97eb-5fe3768b8127","url":"https://aisecwatch.com/issues/6551f2fa-abb7-4573-97eb-5fe3768b8127","cveId":"CVE-2023-36188","title":"CVE-2023-36188: An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the…","headline":"langchain remote code execution via PALChain parameter","severity":"critical","publishedAt":"2023-07-06T18:15:10.663Z","affected":["langchain@< 0.0.247 (fixed: 0.0.247)"],"epssScore":0.01895,"matchedBy":"ecosystem"},{"id":"ea737e84-03c5-4e4b-a791-193855336a51","url":"https://aisecwatch.com/issues/ea737e84-03c5-4e4b-a791-193855336a51","cveId":"CVE-2023-36258","title":"CVE-2023-36258: An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system…","headline":"LangChain arbitrary code execution through os.system, exec, or eval","severity":"critical","publishedAt":"2023-07-04T01:15:09.797Z","affected":["langchain@< 0.0.247 (fixed: 0.0.247)"],"epssScore":0.01074,"matchedBy":"ecosystem"},{"id":"9b5a4e3c-1a8b-47eb-b912-3f8dd664a756","url":"https://aisecwatch.com/issues/9b5a4e3c-1a8b-47eb-b912-3f8dd664a756","cveId":"CVE-2023-34541","title":"CVE-2023-34541: Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.","headline":"Langchain arbitrary code execution in load_prompt","severity":"critical","publishedAt":"2023-06-20T19:15:11.727Z","affected":["langchain@< 0.0.247 (fixed: 0.0.247)"],"epssScore":0.00943,"matchedBy":"ecosystem"},{"id":"32b0f8e8-ad5c-49ef-9714-6f76908949b6","url":"https://aisecwatch.com/issues/32b0f8e8-ad5c-49ef-9714-6f76908949b6","cveId":"CVE-2023-34540","title":"CVE-2023-34540: Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component…","headline":"Langchain remote code execution through JiraAPIWrapper crafted input","severity":"critical","publishedAt":"2023-06-14T19:15:10.287Z","affected":["langchain@< 0.0.225 (fixed: 0.0.225)"],"epssScore":0.01681,"matchedBy":"ecosystem"},{"id":"3382b9a9-8903-4c6b-b336-2d738c1735d4","url":"https://aisecwatch.com/issues/3382b9a9-8903-4c6b-b336-2d738c1735d4","cveId":"CVE-2023-29374","title":"CVE-2023-29374: In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code…","headline":"LangChain LLMMathChain prompt injection leads to arbitrary code execution","severity":"critical","publishedAt":"2023-04-05T06:15:37.340Z","affected":["langchain@<= 0.0.131"],"epssScore":0.39653,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:59:30.540Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}