Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
614102
AlmaLinux
4641
Alpaquita
8775
Alpine
4048
Android
3261
BellSoft Hardened Containers
428
Bitnami
6958
Chainguard
5673
CleanStart
757
CRAN
14
crates.io
2213
Debian
54271
Echo
3170
GHC
3
GIT
81470
GitHub Actions
49
Go
6547
Hackage
30
Hex
57
Julia
483
Linux
15361
Mageia
5871
Maven
6322
MinimOS
25202
npm
217323
NuGet
1657
opam
12
openEuler
6386
openSUSE
12461
OSS-Fuzz
3825
Packagist
6068
Pub
11
PyPI
18664
Red Hat
19213
Rocky Linux
2922
Root
11916
RubyGems
1933
SUSE
20359
SwiftURL
50
Ubuntu
52049
VSCode
18
Wolfi
3631
ID
Packages
Summary
Published
arrow_upward
Attributes
ECHO-34c7-ca18-1a8c
PyPI/langchain-core
See record for full details
2 days ago
Fix available
GHSA-926x-3r5x-gfhw
PyPI/langchain-core
LangChain has incomplete f-string validation in prompt templates
08 Apr
Fix available
Severity - 5.3 (Medium)
GHSA-qh6h-p6c9-ff54
PyPI/langchain-core
LangChain Core has Path Traversal vulnerabilites in legacy
`
load_prompt
`
functions
27 Mar
Fix available
Severity - 7.5 (High)
GHSA-2g6r-c272-w58r
PyPI/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
11 Feb
Fix available
Severity - 3.7 (Low)
GHSA-c67j-w6g6-q2cm
PyPI/langchain-core
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
23 Dec 2025
Fix available
Severity - 9.3 (Critical)
GHSA-6qv9-48xg-fc7f
PyPI/langchain-core
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
20 Nov 2025
Fix available
Severity - 8.3 (High)
GHSA-5chr-fjjv-38qv
PyPI/langchain-core
langchain-core allows unauthorized users to read arbitrary files from the host file system
20 Mar 2025
Fix available
Severity - 5.3 (Medium)
GHSA-q84m-rmw3-4382
PyPI/langchain-core
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
26 Mar 2024
Fix available
Severity - 5.9 (Medium)
GHSA-h59x-p739-982c
PyPI/langchain
PyPI/langchain-core
LangChain directory traversal vulnerability
04 Mar 2024
Fix available
PYSEC-2024-45
PyPI/langchain-core
See record for full details
04 Mar 2024
Fix available
PyPI - OSV