Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17213
  • PyPI/azure-langchain-example
Malicious code in azure-langchain-example (PyPI) 4 days ago
  • No fix available
GHSA-g28h-2cmm-rj9x
  • PyPI/langchain-nvidia-ai-endpoints
langchain-nvidia-ai-endpoints has local file disclosure through VLM image inputs 24 Sep
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-2556
  • PyPI/langchain-anthropic
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders 13 Jul
  • Fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-2555
  • PyPI/langchain
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2560
  • PyPI/langchain-classic
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2564
  • PyPI/langchain-core
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists 13 Jul
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-2557
  • PyPI/langchain-chatchat
Langchain-Chatchat Uses Insufficiently Random Values 13 Jul
  • No fix available
  • Severity - 1.2 (Low)
PYSEC-2026-2559
  • PyPI/langchain-chatchat
Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API 13 Jul
  • No fix available
  • Severity - 1.2 (Low)
PYSEC-2026-2558
  • PyPI/langchain-chatchat
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm 13 Jul
  • No fix available
  • Severity - 1.2 (Low)
PYSEC-2026-2563
  • PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates 13 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2562
  • PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages 13 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-2561
  • PyPI/langchain-community
Denial of service in langchain-community 13 Jul
  • Fix available
  • Severity - 4.2 (Medium)
PYSEC-2026-1070
  • PyPI/langchain-core-mcp
Malicious code in langchain-core-mcp (PyPI) 07 Jul
  • No fix available
PYSEC-2026-1518
  • PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates 07 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-1520
  • PyPI/langchain-text-splitters
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1515
  • PyPI/langchain-community
Langchain Community Vulnerable to XML External Entity (XXE) Attacks 07 Jul
  • Fix available
  • Severity - 7.5 (High)