© 2025-2026 PySpect
First version without a known vulnerability: 1.3.9
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
Fixed in: 1.3.9, 1.4.6
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
Fixed in: 0.8.0, 0.6.0, 1.0.7, 0.3.30
Langchain SQL Injection vulnerability
Fixed in: 0.2.19, 0.2.0
A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.
Fixed in: 0.2.9
Denial of service in langchain-community
Fixed in: 0.2.5, 73c42306745b0831aa6fe7fe4eeb70d2c2d87a82
langchain vulnerable to path traversal
Fixed in: 0.0.353
LangChain directory traversal vulnerability
Fixed in: 0.0.339, 0.1.30, 0.1.11
langchain Server-Side Request Forgery vulnerability
Fixed in: 0.1.0
Langchain Server-Side Request Forgery vulnerability
Fixed in: 0.0.329
Langchain SQL Injection vulnerability
Fixed in: 0.0.247
LangChain Server Side Request Forgery vulnerability
Fixed in: 0.0.317, 9ecb7240a480720ec9d739b3877a52f76098a2b8
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
Fixed in: 0.0.308, 2.8.5
langchain vulnerable to arbitrary code execution
Fixed in: 0.0.312, 0.0.171
LangChain vulnerable to arbitrary code execution
Fixed in: 0.0.236, 0.0.195
LangChain vulnerable to arbitrary code execution
Fixed in: 0.0.247
LangChain vulnerable to arbitrary code execution
Fixed in: 0.0.325, 0.0.233
langchain Code Injection vulnerability
Fixed in: 0.0.236
langchain vulnerable to arbitrary code execution
Fixed in: 0.0.247
langchain SQL Injection vulnerability
Fixed in: 0.0.247
langchain arbitrary code execution vulnerability
Fixed in: 0.0.247
Langchain vulnerable to arbitrary code execution
Fixed in: 0.0.247
Langchain OS Command Injection vulnerability
Fixed in: 0.0.225
LangChain vulnerable to code injection
Fixed in: 0.0.132