© 2025-2026 PySpect
First version without a known vulnerability: 0.3.27
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
Fixed in: 0.3.27
LangChain Community SSRF vulnerability exists in RequestsToolkit component
Fixed in: 0.0.28, e188d4ecb085d4561a0be3c583d26aa9c2c3283f
Langchain SQL Injection vulnerability
Fixed in: 0.2.19, 0.2.0, c2a3021bb0c5f54649d380b42a0684ca5778c255, 0.3.0
LangChain pickle deserialization of untrusted data
Fixed in: 0.2.4
Denial of service in langchain-community
Fixed in: 0.2.5
Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
Fixed in: 0.2.9
A vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.0.27 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-255372.