{"data":{"ecosystem":"pypi","name":"langchain-core","url":"https://aisecwatch.com/packages/pypi/langchain-core","latestVersion":"1.6.9","firstReleaseAt":"2023-11-20T21:11:56.275Z","repository":"https://github.com/langchain-ai/langchain","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-11-20T21:11:56.275Z","integratedVersion":"0.0.1","sdks":["langchain"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:httpx"]},"dependencies":[{"ecosystem":"pypi","name":"langsmith","versionSpec":"<1.0.0,>=0.3.45","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":"<1.0.0,>=0.23.0","scope":"runtime"},{"ecosystem":"pypi","name":"jsonpatch","versionSpec":"<2.0.0,>=1.33.0","scope":"runtime"},{"ecosystem":"pypi","name":"langchain-protocol","versionSpec":">=0.0.17","scope":"runtime"},{"ecosystem":"pypi","name":"packaging","versionSpec":">=23.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3.0.0,>=2.7.4","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":"<7.0.0,>=5.3.0","scope":"runtime"},{"ecosystem":"pypi","name":"tenacity","versionSpec":"!=8.4.0,<10.0.0,>=8.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":"<5.0.0,>=4.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"uuid-utils","versionSpec":"<1.0,>=0.12.0","scope":"runtime"}],"advisories":[{"id":"a39669b8-ec7f-43d1-a668-57adf4667752","url":"https://aisecwatch.com/issues/a39669b8-ec7f-43d1-a668-57adf4667752","cveId":"CVE-2026-44843","title":"GHSA-pjwx-r37v-7724: LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists","severity":"high","publishedAt":"2026-05-08T23:07:32.000Z","affected":["langchain-core@<= 0.3.84 (fixed: 0.3.85)","langchain-core@>= 1.0.0, <= 1.3.2 (fixed: 1.3.3)"],"epssScore":0.00382},{"id":"017abd3b-28ae-45e3-b9f5-dbe910daae2a","url":"https://aisecwatch.com/issues/017abd3b-28ae-45e3-b9f5-dbe910daae2a","cveId":"CVE-2026-40087","title":"CVE-2026-40087: LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's…","severity":"medium","publishedAt":"2026-04-09T20:16:27.400Z","affected":["langchain-core@< 0.3.83 (fixed: 0.3.84)","langchain-core@>= 1.0.0a1, < 1.2.28 (fixed: 1.2.28)"],"epssScore":0.00454},{"id":"d38cf4b3-205f-440a-b5e0-6e6467e20cd0","url":"https://aisecwatch.com/issues/d38cf4b3-205f-440a-b5e0-6e6467e20cd0","cveId":null,"title":"GHSA-926x-3r5x-gfhw: LangChain has incomplete f-string validation in prompt templates","severity":"medium","publishedAt":"2026-04-08T21:51:32.000Z","affected":["langchain-core@>= 1.0.0a1, < 1.2.28 (fixed: 1.2.28)","langchain-core@< 0.3.83 (fixed: 0.3.84)"],"epssScore":null},{"id":"05558de1-b9da-4a50-acca-6fac6c676cee","url":"https://aisecwatch.com/issues/05558de1-b9da-4a50-acca-6fac6c676cee","cveId":"CVE-2026-34070","title":"GHSA-qh6h-p6c9-ff54: LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions","severity":"high","publishedAt":"2026-03-27T19:45:00.000Z","affected":["langchain-core@< 1.2.22 (fixed: 1.2.22)"],"epssScore":0.01213},{"id":"f123ad97-6c35-4b62-a0f5-8c1aef069c49","url":"https://aisecwatch.com/issues/f123ad97-6c35-4b62-a0f5-8c1aef069c49","cveId":"CVE-2026-26013","title":"CVE-2026-26013: LangChain is a framework for building agents and LLM-powered applications. Prior to 1.2.11, the…","severity":"low","publishedAt":"2026-02-11T03:17:00.453Z","affected":["langchain-core@< 1.2.11 (fixed: 1.2.11)"],"epssScore":0.00472},{"id":"ca3f2521-633f-4d72-b991-aff3fe819f97","url":"https://aisecwatch.com/issues/ca3f2521-633f-4d72-b991-aff3fe819f97","cveId":"CVE-2025-68664","title":"CVE-2025-68664: LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a…","severity":"critical","publishedAt":"2025-12-24T04:15:44.933Z","affected":["langchain-core@>= 1.0.0, < 1.2.5 (fixed: 1.2.5)","langchain-core@< 0.3.81 (fixed: 0.3.81)"],"epssScore":0.4293},{"id":"9e980682-4f78-4018-8a9f-277646c612bb","url":"https://aisecwatch.com/issues/9e980682-4f78-4018-8a9f-277646c612bb","cveId":"CVE-2025-65106","title":"CVE-2025-65106: LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to…","severity":"medium","publishedAt":"2025-11-22T03:16:32.933Z","affected":["langchain-core@>= 1.0.0, <= 1.0.6 (fixed: 1.0.7)","langchain-core@<= 0.3.79 (fixed: 0.3.80)"],"epssScore":0.00505},{"id":"b727fd1f-de74-4757-a549-00245fbc5a66","url":"https://aisecwatch.com/issues/b727fd1f-de74-4757-a549-00245fbc5a66","cveId":"CVE-2024-10940","title":"CVE-2024-10940: A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized…","severity":"high","publishedAt":"2025-03-20T14:15:21.850Z","affected":["langchain-core@>= 0.1.17, < 0.1.53 (fixed: 0.1.53)","langchain-core@>= 0.2.0, < 0.2.43 (fixed: 0.2.43)","langchain-core@>= 0.3.0, < 0.3.15 (fixed: 0.3.15)"],"epssScore":0.00388},{"id":"064d6fc4-c22e-4cd1-9330-b00c2c13b41a","url":"https://aisecwatch.com/issues/064d6fc4-c22e-4cd1-9330-b00c2c13b41a","cveId":"CVE-2024-1455","title":"CVE-2024-1455: A vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External…","severity":"medium","publishedAt":"2024-03-26T18:15:08.450Z","affected":["langchain-core@< 0.1.35 (fixed: 0.1.35)"],"epssScore":0.00764},{"id":"07990f4e-8a0a-48ec-a8f1-06723a796686","url":"https://aisecwatch.com/issues/07990f4e-8a0a-48ec-a8f1-06723a796686","cveId":"CVE-2024-28088","title":"CVE-2024-28088: LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path…","severity":"high","publishedAt":"2024-03-04T05:15:47.017Z","affected":["langchain@< 0.0.339 (fixed: 0.0.339)","langchain-core@>= 0, < 0.1.30 (fixed: 0.1.30)"],"epssScore":0.0174}],"checkedAt":"2026-10-09T21:59:32.175Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}