Executive brief
LangChain's XMLOutputParser vulnerable to XML Entity Expansion
Affected products
- PyPI langchain-core
Junglewise Threat Intelligence
CVE-2024-1455 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: langchain-core (PyPI). Vendors: PyPI.
LangChain's XMLOutputParser vulnerable to XML Entity Expansion