{"data":{"ecosystem":"pypi","name":"langchain-anthropic","url":"https://aisecwatch.com/packages/pypi/langchain-anthropic","latestVersion":"1.7.5","firstReleaseAt":"2023-12-20T17:45:39.549Z","repository":"https://github.com/langchain-ai/langchain","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-12-20T17:45:39.549Z","integratedVersion":"0.0.1","sdks":["langchain"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"anthropic","versionSpec":"<2.0.0,>=0.120.0","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2.0.0,>=1.6.6","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3.0.0,>=2.7.4","scope":"runtime"}],"advisories":[{"id":"91cf3a90-9e28-4efc-81cf-044cf29caebf","url":"https://aisecwatch.com/issues/91cf3a90-9e28-4efc-81cf-044cf29caebf","cveId":"CVE-2026-55443","title":"CVE-2026-55443: LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components…","headline":"LangChain path confinement flaws expose files outside intended root","severity":"medium","publishedAt":"2026-06-22T19:17:21.537Z","affected":["langchain@<= 1.3.8 (fixed: 1.3.9)","langchain-anthropic@<= 1.4.5 (fixed: 1.4.6)"],"epssScore":0.0021,"matchedBy":"ecosystem"},{"id":"1526169a-7130-4ea8-92d6-e2e854148727","url":"https://aisecwatch.com/issues/1526169a-7130-4ea8-92d6-e2e854148727","cveId":null,"title":"GHSA-gr75-jv2w-4656: LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","headline":null,"severity":"medium","publishedAt":"2026-06-16T15:03:14.000Z","affected":["langchain-anthropic@<= 1.4.5 (fixed: 1.4.6)","langchain@<= 1.3.8 (fixed: 1.3.9)"],"epssScore":null,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:50:52.275Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}