Technology · PyPI
langchain (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in langchain (PyPI): 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2024-2965, was published on 13 July 2026.
- Last 7 days
- 0
- Last 90 days
- 6
- Critical, all time
- 1
- Exploited in the wild
- 0
About langchain (PyPI)
A framework for developing applications powered by large language models.
Latest langchain (PyPI) vulnerabilities
- CVE-2024-2965: PYSEC-2026-2561 - Denial of service in langchain-communitylowCVSS 3.1EPSS 0.3%
- CVE-2024-8309: PYSEC-2026-1507 - Langchain SQL Injection vulnerabilitylowCVSS 3.1EPSS 13.7%
- CVE-2024-5998: PYSEC-2026-1514 - LangChain pickle deserialization of untrusted datalowCVSS 3.1EPSS 0.4%
- CVE-2024-3571: PYSEC-2026-1510 - langchain vulnerable to path traversallowCVSS 3EPSS 1.9%
- CVE-2024-0243: PYSEC-2026-1509 - langchain Server-Side Request Forgery vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-32786: PYSEC-2026-1508 - Langchain Server-Side Request Forgery vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2023-32785: PYSEC-2026-372 - Langchain SQL Injection vulnerabilitylowCVSS 3.1
- CVE-2026-55443: LangChain path traversal and sandbox escape in file-search middleware and loadersmediumCVSS 5.1EPSS 0.2%
- LangChain path traversal and sandbox escape in file-search and loadersmediumCVSS 5.1
- CVE-2026-45134: LangChain LangSmith SDK untrusted deserialization in prompt pull methodshighCVSS 7.1EPSS 0.3%
- CVE-2024-58340: LangChain ReDoS in MRKLOutputParserhighCVSS 7.5EPSS 0.5%
- PYSEC-2024-111 - A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This…lowCVSS 3.1
- PYSEC-2024-114 - A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this…lowCVSS 3.1
- CVE-2024-28088: PYSEC-2024-45 - LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part…infoEPSS 1.7%
- CVE-2023-46229: PYSEC-2023-205 - LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can…lowCVSS 3.1EPSS 44.7%
- CVE-2023-39631: PYSEC-2023-162 - An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the…lowCVSS 3.1EPSS 1.6%
- CVE-2023-36281: PYSEC-2023-151 - An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json…lowCVSS 3.1EPSS 3.4%
- CVE-2023-39659: PYSEC-2023-147 - An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary…lowCVSS 3.1EPSS 1.5%
- CVE-2023-38860: PYSEC-2023-145 - An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt…lowCVSS 3.1EPSS 1.4%
- CVE-2023-38896: PYSEC-2023-146 - An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary…lowCVSS 3.1EPSS 1.8%
- CVE-2023-36095: PYSEC-2023-138 - An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the…lowCVSS 3.1EPSS 1.2%
- CVE-2023-36188: LangChain remote code execution in PALChain Python exec methodcriticalCVSS 9.8EPSS 1.9%
- CVE-2023-36189: PYSEC-2023-110 - SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive…lowCVSS 3.1EPSS 1.3%
- CVE-2023-36258: PYSEC-2023-98 - An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the…lowCVSS 3.1EPSS 1.1%
- CVE-2023-34541: PYSEC-2023-92 - Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.lowCVSS 3.1EPSS 0.9%
Most severe langchain (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2023-36188: LangChain remote code execution in PALChain Python exec methodcriticalCVSS 9.8EPSS 1.9%
- CVE-2024-58340: LangChain ReDoS in MRKLOutputParserhighCVSS 7.5EPSS 0.5%
- CVE-2026-45134: LangChain LangSmith SDK untrusted deserialization in prompt pull methodshighCVSS 7.1EPSS 0.3%
- CVE-2026-55443: LangChain path traversal and sandbox escape in file-search middleware and loadersmediumCVSS 5.1EPSS 0.2%
- LangChain path traversal and sandbox escape in file-search and loadersmediumCVSS 5.1
- CVE-2023-46229: PYSEC-2023-205 - LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can…lowCVSS 3.1EPSS 44.7%
- CVE-2023-29374: PYSEC-2023-18 - In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute…lowCVSS 3.1EPSS 39.6%
- CVE-2024-8309: PYSEC-2026-1507 - Langchain SQL Injection vulnerabilitylowCVSS 3.1EPSS 13.7%
- CVE-2023-36281: PYSEC-2023-151 - An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json…lowCVSS 3.1EPSS 3.4%
- CVE-2023-38896: PYSEC-2023-146 - An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary…lowCVSS 3.1EPSS 1.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/langchain.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "langchain (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/langchain, 28 September 2026.