CVE-2026-97869: A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the fun
Summary
A vulnerability was found in langchain4j (a framework for building AI applications) up to versions 1.5.3-beta10, 1.11.10-beta18, and 1.18.1-beta27 in a function called AgenticScopeSerializer.fromJson that improperly handles deserialization (converting data back into objects, which can allow attackers to inject malicious code). Remote attackers could potentially exploit this, though it requires high complexity and the application must have a specific feature called AgenticScope persistence enabled.
Solution / Mitigation
Upgrade to version 1.5.3-beta11, 1.11.10-beta19, or 1.18.1-beta28, depending on which release line you are using.
Vulnerability Details
4.1(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
network
high
high
none
September 25, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-97869
First tracked: September 25, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 92%