Executive brief
LangChain is a popular JavaScript library framework for building AI applications. A flaw in its serialization mechanism allows attackers who control data passed through the library to inject malicious structures that extract environment variable secrets (like API keys) or instantiate arbitrary classes when the data is later deserialized. This is particularly dangerous in applications that process untrusted LLM responses or user-supplied metadata.
Technical details
The vulnerability is a serialization injection flaw in LangChain JS's toJSON() method. The method failed to escape user-controlled objects containing 'lc' keys (used internally to mark serialized LangChain objects) within kwargs like additional_kwargs, metadata, or response_metadata. During deserialization via load(), these injected structures were incorrectly treated as legitimate LangChain objects rather than plain data. This allowed attackers to inject secret extraction payloads ({"lc": 1, "type": "secret", "id": ["ENV_VAR"]}) that would leak environment variables when secretsFromEnv was enabled, or to instantiate arbitrary classes from provided import maps with controlled parameters. Attack preconditions include either: serializing untrusted data followed by deserialization, or directly deserializing untrusted data. The patch adds an escape mechanism in toJSON(), changes secretsFromEnv default to false, and introduces a maxDepth parameter for DoS protection.
Affected products
- LangChain @langchain/core < 1.1.8 (when >= 1.0.0), < 0.3.80
- LangChain langchain < 1.2.3 (when >= 1.0.0), < 0.3.37
Timeline
- 2025-12-23: disclosed
- 2025-12-23: patched: @langchain/core 1.1.8 and 0.3.80; langchain 1.2.3 and 0.3.37