Записи LangChain
49 опубликованных записей вендора langchain.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 15
- С записью об исправлении
- 95,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-918 Server-Side Request Forgery (SSRF)10
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-502 Deserialization of Untrusted Data6
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-29374Эксплойта нет | In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec metlangchain · langchain · CWE-74 | Критическая9,8 | — | 39,7 % | 4 апр. 2023 г. |
48В плане | CVE-2023-46229Proof of concept | LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to anlangchain · langchain · CWE-918 | Высокая8,8 | — | 44,7 % | 19 окт. 2023 г. |
46В плане | CVE-2025-2828Эксплойта нет | SSRF Vulnerability in RequestsToolkit in langchain-ai/langchainlangchain · langchain · CWE-918 | Критическая10,0 | — | 21,0 % | 23 июн. 2025 г. |
45В плане | CVE-2025-68664Proof of concept | LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIslangchain · langchain core · CWE-502 | Высокая8,2 | — | 42,9 % | 23 дек. 2025 г. |
43В плане | CVE-2024-8309Proof of concept | SQL Injection in langchain-ai/langchainlangchain · langchain · CWE-89 | Критическая9,8 | — | 13,7 % | 29 окт. 2024 г. |
40В плане | CVE-2023-36281Proof of concept | An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt.langchain · langchain · CWE-94 | Критическая9,8 | — | 3,4 % | 22 авг. 2023 г. |
40В плане | CVE-2023-36188Эксплойта нет | An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.langchain · langchain · CWE-74 | Критическая9,8 | — | 1,9 % | 6 июл. 2023 г. |
40В плане | CVE-2023-38896Эксплойта нет | An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and frlangchain · langchain · CWE-74 | Критическая9,8 | — | 1,8 % | 15 авг. 2023 г. |
40В плане | CVE-2023-34540Эксплойта нет | Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRlangchain · langchain | Критическая9,8 | — | 1,7 % | 14 июн. 2023 г. |
39Наблюдать | CVE-2023-39631Эксплойта нет | An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr librlangchain · langchain · CWE-94 | Критическая9,8 | — | 1,6 % | 1 сент. 2023 г. |
39Наблюдать | CVE-2023-39659Эксплойта нет | An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the Pytholangchain · langchain · CWE-74 | Критическая9,8 | — | 1,5 % | 15 авг. 2023 г. |
39Наблюдать | CVE-2023-38860Эксплойта нет | An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.langchain · langchain · CWE-94 | Критическая9,8 | — | 1,4 % | 15 авг. 2023 г. |
39Наблюдать | CVE-2024-46946Эксплойта нет | langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sylangchain · langchain-experimental · CWE-20 | Критическая9,8 | — | 1,4 % | 19 сент. 2024 г. |
39Наблюдать | CVE-2023-36095Эксплойта нет | An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affeclangchain · langchain · CWE-94 | Критическая9,8 | — | 1,2 % | 4 авг. 2023 г. |
39Наблюдать | CVE-2023-36258Эксплойта нет | An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be ulangchain · langchain · CWE-94 | Критическая9,8 | — | 1,1 % | 3 июл. 2023 г. |
39Наблюдать | CVE-2023-44467Эксплойта нет | langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execlangchain · langchain experimental | Критическая9,8 | — | 1,0 % | 9 окт. 2023 г. |
39Наблюдать | CVE-2023-34541Эксплойта нет | Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.langchain · langchain | Критическая9,8 | — | 0,9 % | 20 июн. 2023 г. |
39Наблюдать | CVE-2024-27444Эксплойта нет | langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and executlangchain · langchain-experimental · CWE-749 | Критическая9,8 | — | 0,8 % | 26 февр. 2024 г. |
39Наблюдать | CVE-2024-2057Эксплойта нет | LangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgerylangchain · langchain · CWE-918 | Критическая9,8 | — | 0,6 % | 1 мар. 2024 г. |
39Наблюдать | CVE-2026-40190Эксплойта нет | LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`langchain · langsmith · CWE-1321 | Критическая9,8 | — | 0,4 % | 10 апр. 2026 г. |
39Наблюдать | CVE-2024-7042Эксплойта нет | Prompt Injection in langchain-ai/langchainjs Leading to SQL Injectionlangchain · langchain · CWE-89 | Критическая9,8 | — | 0,3 % | 29 окт. 2024 г. |
36Наблюдать | CVE-2024-3571Эксплойта нет | Path Traversal in langchain-ai/langchainlangchain · langchain · CWE-22 | Высокая8,8 | — | 1,9 % | 15 апр. 2024 г. |
36Наблюдать | CVE-2025-68665Эксплойта нет | LangChain serialization injection vulnerability enables secret extractionlangchain · langchain.js · CWE-502 | Критическая9,1 | — | 0,8 % | 23 дек. 2025 г. |
36Наблюдать | CVE-2024-7774Эксплойта нет | Path Traversal in langchain-ai/langchainjslangchain · langchain.js · CWE-29 | Критическая9,1 | — | 0,6 % | 29 окт. 2024 г. |
36Наблюдать | CVE-2026-48776Эксплойта нет | LangGraph SDK has unsafe URL path constructionlangchain · langgraph-sdk · CWE-22 | Критическая9,1 | — | 0,3 % | 17 июн. 2026 г. |
- CVE-2023-2937451В плане
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec met
КритическаяCVSS 9,8Эксплойта нетEPSS 40 %langchain · langchain4 апр. 2023 г.
- CVE-2023-4622948В плане
LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an
ВысокаяCVSS 8,8Proof of conceptEPSS 45 %langchain · langchain19 окт. 2023 г.
- CVE-2025-282846В плане
SSRF Vulnerability in RequestsToolkit in langchain-ai/langchain
КритическаяCVSS 10,0Эксплойта нетEPSS 21 %langchain · langchain23 июн. 2025 г.
- CVE-2025-6866445В плане
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
ВысокаяCVSS 8,2Proof of conceptEPSS 43 %langchain · langchain core23 дек. 2025 г.
- CVE-2024-830943В плане
SQL Injection in langchain-ai/langchain
КритическаяCVSS 9,8Proof of conceptEPSS 14 %langchain · langchain29 окт. 2024 г.
- CVE-2023-3628140В плане
An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %langchain · langchain22 авг. 2023 г.
- CVE-2023-3618840В плане
An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %langchain · langchain6 июл. 2023 г.
- CVE-2023-3889640В плане
An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and fr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %langchain · langchain15 авг. 2023 г.
- CVE-2023-3454040В плане
Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIR
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %langchain · langchain14 июн. 2023 г.
- CVE-2023-3963139Наблюдать
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr libr
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %langchain · langchain1 сент. 2023 г.
- CVE-2023-3965939Наблюдать
An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the Pytho
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %langchain · langchain15 авг. 2023 г.
- CVE-2023-3886039Наблюдать
An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain15 авг. 2023 г.
- CVE-2024-4694639Наблюдать
langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sy
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain-experimental19 сент. 2024 г.
- CVE-2023-3609539Наблюдать
An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affec
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain4 авг. 2023 г.
- CVE-2023-3625839Наблюдать
An issue in LangChain before 0.0.236 allows an attacker to execute arbitrary code because Python code with os.system, exec, or eval can be u
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain3 июл. 2023 г.
- CVE-2023-4446739Наблюдать
langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and exec
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain experimental9 окт. 2023 г.
- CVE-2023-3454139Наблюдать
Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain20 июн. 2023 г.
- CVE-2024-2744439Наблюдать
langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execut
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain-experimental26 февр. 2024 г.
- CVE-2024-205739Наблюдать
LangChain langchain_community TFIDFRetriever tfidf.py load_local server-side request forgery
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %langchain · langchain1 мар. 2024 г.
- CVE-2026-4019039Наблюдать
LangSmith Client SDKs has Prototype Pollution in langsmith-sdk via Incomplete `__proto__` Guard in Internal lodash `set()`
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %langchain · langsmith10 апр. 2026 г.
- CVE-2024-704239Наблюдать
Prompt Injection in langchain-ai/langchainjs Leading to SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %langchain · langchain29 окт. 2024 г.
- CVE-2024-357136Наблюдать
Path Traversal in langchain-ai/langchain
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %langchain · langchain15 апр. 2024 г.
- CVE-2025-6866536Наблюдать
LangChain serialization injection vulnerability enables secret extraction
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %langchain · langchain.js23 дек. 2025 г.
- CVE-2024-777436Наблюдать
Path Traversal in langchain-ai/langchainjs
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %langchain · langchain.js29 окт. 2024 г.
- CVE-2026-4877636Наблюдать
LangGraph SDK has unsafe URL path construction
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %langchain · langgraph-sdk17 июн. 2026 г.