VDB
Sign up
MEDIUM5.2

PYSEC-2026-1514

LangChain pickle deserialization of untrusted data

Quick fix

PYSEC-2026-1514 — langchain-community: upgrade to the fixed version with the command below.

pip install --upgrade 'langchain-community>=0.2.4'

Details

A vulnerability in the `FAISS.deserialize_from_bytes` function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the `os.system` function. The issue affects versions prior to 0.2.4.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/langchain-community
Introduced in: 0Fixed in: 0.2.4
Fixpip install --upgrade 'langchain-community>=0.2.4'

References