Junglewise Threat Intelligence

CVE-2025-6985: PYSEC-2026-1520 - LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

CVE-2025-6985 · Severity: low · CVSS 3 · Published 2026-07-07

Vendors: PyPI.

Executive brief

LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing

Affected products

  • PyPI langchain-text-splitters

Related threats