11 Total advisories
11 Vulnerabilities
0 Malware
Dependency scanning
Check whether langchain-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.3
CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
CRITICAL 9.3
CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
UNKNOWN
CVE-2024-28088
CVE-2024-28088
HIGH 8.2
CVE-2026-44843
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
HIGH 7.5
CVE-2026-34070
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
MEDIUM 5.3
CVE-2026-40087
LangChain has incomplete f-string validation in prompt templates
LOW 3.7
CVE-2026-26013
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
UNKNOWN
CVE-2025-65106
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
MEDIUM 5.3
CVE-2024-10940
langchain-core allows unauthorized users to read arbitrary files from the host file system
UNKNOWN
CVE-2024-28088
LangChain directory traversal vulnerability
MEDIUM 5.9
CVE-2024-1455
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes