© 2025-2026 PySpect
First version without a known vulnerability: 1.4.0a1
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
Fixed in: 1.3.3, 0.3.85
LangChain has incomplete f-string validation in prompt templates
Fixed in: 0.3.84, 1.2.28
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
Fixed in: 1.2.22
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Fixed in: 1.2.11
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Fixed in: 1.2.5, 0.3.81
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
Fixed in: 1.0.7, 0.3.80
langchain-core allows unauthorized users to read arbitrary files from the host file system
Fixed in: 0.1.53, 0.2.43, 0.3.15
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Fixed in: 0.1.35
LangChain directory traversal vulnerability
Fixed in: 0.0.339, 0.1.30, 0.1.11