Dependency scanning
Check whether langchain is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-45134
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2023-32785
Langchain SQL Injection vulnerability
CVE-2023-32785
Langchain SQL Injection vulnerability
GHSA-gr75-jv2w-4656
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2023-36281
CVE-2023-36281
CVE-2023-39659
CVE-2023-39659
CVE-2023-38896
CVE-2023-38896
CVE-2023-38860
CVE-2023-38860
CVE-2023-36095
CVE-2023-36095
CVE-2024-8309
CVE-2024-8309
CVE-2024-2965
CVE-2024-2965
CVE-2023-36258
CVE-2023-36258
CVE-2023-34541
CVE-2023-34541
CVE-2023-34540
CVE-2023-34540
CVE-2023-46229
CVE-2023-46229
CVE-2023-29374
CVE-2023-29374
CVE-2023-36188
CVE-2023-36188
CVE-2023-36189
CVE-2023-36189
PYSEC-2024-111
PYSEC-2024-111
CVE-2024-0243
langchain Server-Side Request Forgery vulnerability
CVE-2023-34540
Langchain OS Command Injection vulnerability
CVE-2023-39631
Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr library
CVE-2023-36188
langchain vulnerable to arbitrary code execution
CVE-2023-29374
LangChain vulnerable to code injection
CVE-2023-34541
Langchain vulnerable to arbitrary code execution
CVE-2024-28088
LangChain directory traversal vulnerability
CVE-2023-36258
langchain arbitrary code execution vulnerability
CVE-2024-8309
Langchain SQL Injection vulnerability
PYSEC-2024-114
PYSEC-2024-114
CVE-2024-2965
Denial of service in langchain-community
CVE-2023-36189
langchain SQL Injection vulnerability
CVE-2023-36281
langchain vulnerable to arbitrary code execution
CVE-2023-46229
LangChain Server Side Request Forgery vulnerability
CVE-2023-38896
LangChain vulnerable to arbitrary code execution
CVE-2023-39659
LangChain vulnerable to arbitrary code execution
CVE-2023-36095
langchain Code Injection vulnerability
CVE-2023-38860
LangChain vulnerable to arbitrary code execution
CVE-2024-3571
langchain vulnerable to path traversal
CVE-2024-28088
CVE-2024-28088
CVE-2023-32786
Langchain Server-Side Request Forgery vulnerability
CVE-2023-39631
CVE-2023-39631
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes