CVE MEDIUM CVE-2026-27795

LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates

CVE MEDIUM CVE-2026-26019

LangChain is a framework for building LLM-powered applications. Prior to 1.1.14, the RecursiveUrlLoader class in @langchain/community is a web crawler that recursively follows links from a starting

CVSS 4.1 langchain_community View details
CVE MEDIUM CVE-2025-58177

stored cross-site scripting (XSS) vulnerability in @n8n/n8n-nodes-langchain.chatTrigger. An authorized user can configure the LangChain Chat Trigger node with malicious JavaScript in the initialMessages field and enable public access

CVSS 5.4 n8n View details
CVE MEDIUM CVE-2025-6854

vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path

CVSS 4.3 langchain-chatchat View details
CVE MEDIUM CVE-2024-10940

vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability

CVSS 5.3 langchain-core View details
CVE MEDIUM CVE-2024-2965

Denial of service in langchain-community

CVSS 4.2 langchain View details
CVE MEDIUM CVE-2024-1455

vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within

CVSS 5.9 langchain View details
CVE MEDIUM CVE-2026-28277

LangGraph checkpoint loading has unsafe msgpack deserialization

CVSS 6.8 langgraph View details