Executive brief
LangChain, a popular framework for building AI applications, contains a vulnerability in how it handles certain data formats. An attacker could send specially crafted data to an application using LangChain to trick it into creating unintended objects. This could lead to chat history tampering, unauthorized access to credentials, or the ability to manipulate the AI's behavior.
Technical details
LangChain contains a deserialization vulnerability (CWE-502) in older runtime code paths that use overly broad object allowlists (allowed_objects='all'). While it does not allow arbitrary Python object deserialization, it permits the revival of any trusted LangChain-serializable object with attacker-supplied constructor arguments. This can be exploited if an application accepts untrusted JSON input and passes it to affected APIs like RunnableWithMessageHistory, astream_log(), or astream_events(). Attackers can instantiate unexpected classes to achieve prompt injection, credential disclosure, or server-side requests. A related secret-marker validation bypass in _is_lc_secret was also identified and fixed. Patches are available in versions 1.3.3 and 0.3.85.
Affected products
- LangChain langchain-core >= 1.0.0, <= 1.3.2; <= 0.3.84
Timeline
- 2026-05-05: disclosed
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-26: other: NVD published