Junglewise Threat Intelligence

CVE-2026-40087: LangChain incomplete f-string validation in prompt templates

CVE-2026-40087 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: langchain-core (PyPI). Vendors: LangChain, PyPI.

Executive brief

LangChain, a framework for building AI applications, had a flaw in how it validated prompt templates. If an application allows users to provide their own template strings, an attacker could craft a template that accesses internal data or sensitive object properties. This could lead to the exposure of private information in the AI's output or application logs.

Technical details

LangChain's f-string validation failed to properly sanitize input in DictPromptTemplate and ImagePromptTemplate, and failed to reject nested replacement fields within format specifiers. This vulnerability allows for improper neutralization of special elements (CWE-1336) and improper input validation (CWE-20). An attacker who can provide untrusted template strings can use Python attribute access (e.g., .__class__) or indexing to traverse internal objects passed into the template during formatting. This can result in the disclosure of internal fields or sensitive data to the model context or logs. The issue is resolved in langchain-core versions 0.3.84 and 1.2.28 by enforcing consistent f-string safety validation and rejecting nested replacement fields.

Affected products

  • LangChain langchain-core < 0.3.83, >= 1.0.0a1, < 1.2.28

Timeline

  • 2026-04-08: advisory: GitHub Advisory GHSA-926x-3r5x-gfhw published
  • 2026-04-08: patched: Fixes merged in PR #36612 and #36613
  • 2026-04-09: other: NVD published CVE-2026-40087

References

Related threats