18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether langchain-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-44843
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
MEDIUM 5.3
CVE-2026-40087
LangChain has incomplete f-string validation in prompt templates
HIGH 7.5
CVE-2026-34070
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
LOW 3.7
CVE-2026-26013
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CRITICAL 9.3
CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
UNKNOWN
CVE-2025-65106
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
HIGH 8.2
CVE-2026-44843
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
MEDIUM 5.3
CVE-2026-40087
LangChain has incomplete f-string validation in prompt templates
LOW 3.7
CVE-2026-26013
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
HIGH 7.5
CVE-2026-34070
CVE-2026-34070
MEDIUM 5.9
CVE-2024-1455
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
MEDIUM 5.3
CVE-2024-10940
langchain-core allows unauthorized users to read arbitrary files from the host file system
MEDIUM 5.3
CVE-2024-10940
langchain-core allows unauthorized users to read arbitrary files from the host file system
UNKNOWN
CVE-2025-65106
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
MEDIUM 5.9
CVE-2024-1455
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
CRITICAL 9.3
CVE-2025-68664
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
UNKNOWN
CVE-2024-28088
CVE-2024-28088
UNKNOWN
CVE-2024-28088
LangChain directory traversal vulnerability
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes