Loading
Building applications with LLMs through composability
Declares an LLM dependency since 2023-11-20 (version 0.0.1).
Advisories that name langchain-core as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-44843GHSA-pjwx-r37v-7724: LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists | High | <= 0.3.84 | 0.3.85 | 2026-05-08 |
| GHSA-926x-3r5x-gfhw: LangChain has incomplete f-string validation in prompt templates | Medium | >= 1.0.0a1, < 1.2.28 | 1.2.28 | 2026-04-08 |
| CVE-2026-34070GHSA-qh6h-p6c9-ff54: LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions | High | < 1.2.22 | 1.2.22 | 2026-03-27 |
As declared in PyPI metadata for version 1.6.9. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.