Перейти к содержимому
Noroxi

Записи LangChain

49 опубликованных записей вендора langchain.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
15
С записью об исправлении
95,9 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

49 записей
  • CVE-2023-29374
    51В плане

    In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec met

    КритическаяCVSS 9,8Эксплойта нетEPSS 40 %

    langchain · langchain4 апр. 2023 г.

  • CVE-2023-46229
    48В плане

    LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an

    ВысокаяCVSS 8,8Proof of conceptEPSS 45 %

    langchain · langchain19 окт. 2023 г.

  • CVE-2025-2828
    46В плане

    SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain

    КритическаяCVSS 10,0Эксплойта нетEPSS 21 %

    langchain · langchain23 июн. 2025 г.

  • CVE-2025-68664
    45В плане

    LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs

    ВысокаяCVSS 8,2Proof of conceptEPSS 43 %

    langchain · langchain core23 дек. 2025 г.

  • CVE-2024-8309
    43В плане

    SQL Injection in langchain-ai/langchain

    КритическаяCVSS 9,8Proof of conceptEPSS 14 %

    langchain · langchain29 окт. 2024 г.

  • CVE-2023-36281
    40В плане

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt.

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    langchain · langchain22 авг. 2023 г.

  • CVE-2023-36188
    40В плане

    An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    langchain · langchain6 июл. 2023 г.

  • CVE-2023-38896
    40В плане

    An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and fr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    langchain · langchain15 авг. 2023 г.

  • CVE-2023-34540
    40В плане

    Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIR

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    langchain · langchain14 июн. 2023 г.

  • CVE-2023-39631
    39Наблюдать

    An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr libr

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    langchain · langchain1 сент. 2023 г.

  • CVE-2023-39659
    39Наблюдать

    An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the Pytho

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    langchain · langchain15 авг. 2023 г.

  • CVE-2023-38860
    39Наблюдать

    An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain15 авг. 2023 г.

  • CVE-2024-46946
    39Наблюдать

    langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sy

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain-experimental19 сент. 2024 г.

  • CVE-2023-36095
    39Наблюдать

    An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affec

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain4 авг. 2023 г.

  • CVE-2023-36258
    39Наблюдать

    An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be u

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain3 июл. 2023 г.

  • CVE-2023-44467
    39Наблюдать

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and exec

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain experimental9 окт. 2023 г.

  • CVE-2023-34541
    39Наблюдать

    Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain20 июн. 2023 г.

  • CVE-2024-27444
    39Наблюдать

    langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execut

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain-experimental26 февр. 2024 г.

  • CVE-2024-2057
    39Наблюдать

    LangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgery

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    langchain · langchain1 мар. 2024 г.

  • CVE-2026-40190
    39Наблюдать

    LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    langchain · langsmith10 апр. 2026 г.

  • CVE-2024-7042
    39Наблюдать

    Prompt Injection in langchain-ai/langchainjs Leading to SQL Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    langchain · langchain29 окт. 2024 г.

  • CVE-2024-3571
    36Наблюдать

    Path Traversal in langchain-ai/langchain

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    langchain · langchain15 апр. 2024 г.

  • CVE-2025-68665
    36Наблюдать

    LangChain serialization injection vulnerability enables secret extraction

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    langchain · langchain.js23 дек. 2025 г.

  • CVE-2024-7774
    36Наблюдать

    Path Traversal in langchain-ai/langchainjs

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    langchain · langchain.js29 окт. 2024 г.

  • CVE-2026-48776
    36Наблюдать

    LangGraph SDK has unsafe URL path construction

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    langchain · langgraph-sdk17 июн. 2026 г.