pypi

langchain-core

View on pypi registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether langchain-core is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 8.2
PyPI

CVE-2026-44843

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

MEDIUM 5.3
PyPI

CVE-2026-40087

LangChain has incomplete f-string validation in prompt templates

HIGH 7.5
PyPI

CVE-2026-34070

LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions

LOW 3.7
PyPI

CVE-2026-26013

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

CRITICAL 9.3
PyPI

CVE-2025-68664

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

UNKNOWN
PyPI

CVE-2025-65106

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

HIGH 8.2
PyPI

CVE-2026-44843

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

MEDIUM 5.3
PyPI

CVE-2026-40087

LangChain has incomplete f-string validation in prompt templates

LOW 3.7
PyPI

CVE-2026-26013

LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages

HIGH 7.5
PyPI

CVE-2026-34070

CVE-2026-34070

MEDIUM 5.9
PyPI

CVE-2024-1455

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

MEDIUM 5.3
PyPI

CVE-2024-10940

langchain-core allows unauthorized users to read arbitrary files from the host file system

MEDIUM 5.3
PyPI

CVE-2024-10940

langchain-core allows unauthorized users to read arbitrary files from the host file system

UNKNOWN
PyPI

CVE-2025-65106

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

MEDIUM 5.9
PyPI

CVE-2024-1455

LangChain's XMLOutputParser vulnerable to XML Entity Expansion

CRITICAL 9.3
PyPI

CVE-2025-68664

LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

UNKNOWN
PyPI

CVE-2024-28088

CVE-2024-28088

UNKNOWN
PyPI

CVE-2024-28088

LangChain directory traversal vulnerability

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes