{"data":{"ecosystem":"pypi","name":"langchain-community","url":"https://aisecwatch.com/packages/pypi/langchain-community","latestVersion":"0.4.2","firstReleaseAt":"2023-12-08T22:26:25.562Z","repository":"https://github.com/langchain-ai/langchain-community/tree/main/libs/community","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-12-08T22:26:25.562Z","integratedVersion":"0.0.1rc1","sdks":["langchain"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:aiohttp","pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"langchain-classic","versionSpec":"<2.0.0,>=1.0.7","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-core","versionSpec":"<2.0.0,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"langsmith","versionSpec":"<1.0.0,>=0.1.125","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4.0.0,>=3.8.3","scope":"runtime"},{"ecosystem":"pypi","name":"httpx-sse","versionSpec":"<1.0.0,>=0.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.26.2","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic-settings","versionSpec":"<3.0.0,>=2.10.1","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":"<7.0.0,>=5.3.0","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"<3.0.0,>=2.32.5","scope":"runtime"},{"ecosystem":"pypi","name":"sqlalchemy","versionSpec":"<3.0.0,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"tenacity","versionSpec":"!=8.4.0,<10.0.0,>=8.1.0","scope":"runtime"}],"advisories":[{"id":"2650b2d0-7c05-4a8f-9dc6-24cc37285c80","url":"https://aisecwatch.com/issues/2650b2d0-7c05-4a8f-9dc6-24cc37285c80","cveId":"CVE-2025-6984","title":"CVE-2025-6984: The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity…","headline":"langchain EverNoteLoader XML external entity injection in XML parsing","severity":"high","publishedAt":"2025-09-04T14:42:33.990Z","affected":["langchain-community@< 0.3.27 (fixed: 0.3.27)"],"epssScore":0.01647,"matchedBy":"ecosystem"},{"id":"dcde1755-3c9a-4cee-8898-465085895f6f","url":"https://aisecwatch.com/issues/dcde1755-3c9a-4cee-8898-465085895f6f","cveId":"CVE-2025-2828","title":"CVE-2025-2828: A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community…","headline":"langchain-community RequestsToolkit SSRF allows access to local addresses","severity":"critical","publishedAt":"2025-06-24T01:15:25.210Z","affected":["langchain-community@< 0.0.28 (fixed: 0.0.28)"],"epssScore":0.21019,"matchedBy":"ecosystem"},{"id":"8b806c72-5762-4757-b287-3889235e009f","url":"https://aisecwatch.com/issues/8b806c72-5762-4757-b287-3889235e009f","cveId":"CVE-2024-8309","title":"CVE-2024-8309: A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection…","headline":"langchain GraphCypherQAChain SQL injection through prompt injection","severity":"critical","publishedAt":"2024-10-29T17:15:10.950Z","affected":["langchain@< 0.2.0 (fixed: 0.2.0)","langchain-community@>= 0.2.0, < 0.2.19 (fixed: 0.2.19)"],"epssScore":0.13738,"matchedBy":"ecosystem"},{"id":"362b9e4c-ecdc-49e0-a1ad-8dccc481881a","url":"https://aisecwatch.com/issues/362b9e4c-ecdc-49e0-a1ad-8dccc481881a","cveId":"CVE-2024-5998","title":"CVE-2024-5998: A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle…","headline":"langchain FAISS.deserialize_from_bytes unsafe pickle deserialization","severity":"high","publishedAt":"2024-09-17T16:15:02.977Z","affected":["langchain-community@< 0.2.4 (fixed: 0.2.4)"],"epssScore":0.00361,"matchedBy":"ecosystem"},{"id":"1610e3cb-2328-451c-bb90-e7a04230b884","url":"https://aisecwatch.com/issues/1610e3cb-2328-451c-bb90-e7a04230b884","cveId":"CVE-2024-3095","title":"CVE-2024-3095: A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of…","headline":"langchain Web Research Retriever SSRF to local and internal addresses","severity":"high","publishedAt":"2024-06-06T23:15:59.160Z","affected":["langchain-community@< 0.2.9 (fixed: 0.2.9)"],"epssScore":0.00691,"matchedBy":"ecosystem"},{"id":"782033d4-5b70-456e-a296-8286fec016eb","url":"https://aisecwatch.com/issues/782033d4-5b70-456e-a296-8286fec016eb","cveId":"CVE-2024-2965","title":"GHSA-3hjh-jh2h-vrg6: Denial of service in langchain-community","headline":null,"severity":"medium","publishedAt":"2024-06-06T21:30:36.000Z","affected":["langchain-community@< 0.2.5 (fixed: 0.2.5)","langchain@>= 0, < 0.2.5 (fixed: 0.2.5)"],"epssScore":0.00304,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:59:34.755Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}