Junglewise Threat Intelligence

CVE-2026-34070: LangChain langchain-core path traversal in prompt loading functions

CVE-2026-34070 · Severity: high · CVSS 7.5 · Published 2026-03-31

Technologies: langchain-core (PyPI). Vendors: LangChain, PyPI.

Executive brief

LangChain is a popular framework used to build applications powered by Artificial Intelligence and Large Language Models. A security flaw in its prompt-loading component allows attackers to read sensitive files from the server's filesystem, such as API keys, cloud credentials, and configuration files. This occurs when an application processes untrusted configuration data, potentially leading to a full compromise of service credentials and private data.

Technical details

A path traversal vulnerability (CWE-22) exists in langchain_core.prompts.loading within the load_prompt() and load_prompt_from_config() functions. These functions fail to validate file paths embedded in deserialized configuration dictionaries against directory traversal (../) or absolute path injection. An attacker can exploit this by providing a crafted configuration to read arbitrary files on the host, limited only by file extension checks (.txt, .json, .yaml). The vulnerability affects legacy, undocumented APIs that have been deprecated in favor of the more secure langchain_core.load serialization model. A patch is available in version 1.2.22 which introduces path validation and an explicit allow_dangerous_paths flag.

Affected products

  • LangChain langchain-core < 1.2.22
  • LangChain langchain < 1.2.22

Timeline

  • 2026-03-24: patched: Fix committed to repository and version 1.2.22 released.
  • 2026-03-26: advisory: GitHub Security Advisory GHSA-qh6h-p6c9-ff54 published.
  • 2026-03-31: disclosed: CVE-2026-34070 published to NVD.

References

Related threats