Executive brief
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
Affected products
- PyPI langchain-text-splitters
Junglewise Threat Intelligence
CVE-2025-6985 · Severity: low · CVSS 3 · Published 2026-07-07
Vendors: PyPI.
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing