Junglewise Threat Intelligence

CVE-2024-10940: PYSEC-2026-1517 - langchain-core allows unauthorized users to read arbitrary files from the host file system

CVE-2024-10940 · Severity: low · CVSS 3 · Published 2026-07-07

Technologies: langchain-core (PyPI). Vendors: PyPI.

Executive brief

langchain-core allows unauthorized users to read arbitrary files from the host file system

Affected products

  • PyPI langchain-core

Related threats