LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Modified: 9/10/2026
package
pkg:pypi/langchain-core
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Modified: 9/10/2026
langchain-core allows unauthorized users to read arbitrary files from the host file system
Modified: 7/7/2026
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
Modified: 9/10/2026
LangChain has incomplete f-string validation in prompt templates
Modified: 9/10/2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Modified: 9/10/2026
LangChain directory traversal vulnerability
Modified: 12/3/2024
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
Modified: 9/10/2026
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Modified: 7/7/2026
LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
Modified: 9/10/2026
Modified: 6/10/2026
langchain-core allows unauthorized users to read arbitrary files from the host file system
Modified: 7/7/2026
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
Modified: 7/7/2026
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Modified: 7/7/2026
Modified: 7/13/2026
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
Modified: 7/13/2026
LangChain has incomplete f-string validation in prompt templates
Modified: 7/13/2026
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
Modified: 7/13/2026
LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs
Modified: 7/2/2026