Loading
Building applications with LLMs through composability
Declares an LLM dependency since 2022-10-25 (version 0.0.1).
Advisories that name langchain as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| GHSA-gr75-jv2w-4656: LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders | Medium | <= 1.3.8 | 1.3.9 | 2026-06-16 |
| CVE-2026-45134GHSA-3644-q5cj-c5c7: LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning | High | < 0.3.30 | 0.3.30 | 2026-05-13 |
As declared in PyPI metadata for version 1.4.4. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.