{"schema_version":1,"title":"langchain-core (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 9 vulnerabilities in langchain-core (PyPI): 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-26013, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/langchain-core","json_url":"https://junglewise.ai/threats/technologies/langchain-core.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/langchain-core","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":9,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":8},"latest":[{"cve":"CVE-2026-26013","cvss":3.1,"epss":0.0042,"slug":"cve-2026-26013-langchain-chatopenai-server-side-request-forgery-via-image-token","title":"PYSEC-2026-2562 - LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:35.874621+00:00","url":"https://junglewise.ai/threats/cve-2026-26013-langchain-chatopenai-server-side-request-forgery-via-image-token"},{"cve":"CVE-2025-65106","cvss":4,"epss":0.0051,"slug":"cve-2025-65106-langchain-vulnerable-to-template-injection-via-attribute-access","title":"PYSEC-2026-1518 - LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:10.501462+00:00","url":"https://junglewise.ai/threats/cve-2025-65106-langchain-vulnerable-to-template-injection-via-attribute-access"},{"cve":"CVE-2024-10940","cvss":3,"epss":0.0039,"slug":"cve-2024-10940-langchain-core-allows-unauthorized-users-to-read-arbitrary-files","title":"PYSEC-2026-1517 - langchain-core allows unauthorized users to read arbitrary files from the host file system","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:52.475462+00:00","url":"https://junglewise.ai/threats/cve-2024-10940-langchain-core-allows-unauthorized-users-to-read-arbitrary-files"},{"cve":"CVE-2024-1455","cvss":3,"epss":0.0077,"slug":"cve-2024-1455-langchain-s-xmloutputparser-vulnerable-to-xml-entity-expansion","title":"PYSEC-2026-1519 - LangChain's XMLOutputParser vulnerable to XML Entity Expansion","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.601622+00:00","url":"https://junglewise.ai/threats/cve-2024-1455-langchain-s-xmloutputparser-vulnerable-to-xml-entity-expansion"},{"cve":"CVE-2025-68664","cvss":3.1,"epss":0.4293,"slug":"cve-2025-68664-langchain-serialization-injection-vulnerability-enables-secret","title":"PYSEC-2026-373 - LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:38.732432+00:00","url":"https://junglewise.ai/threats/cve-2025-68664-langchain-serialization-injection-vulnerability-enables-secret"},{"cve":"CVE-2026-44843","cvss":8.2,"epss":0.0038,"slug":"cve-2026-44843-langchain-unsafe-deserialization-in-load-via-broad-object","title":"LangChain unsafe deserialization in load() via broad object allowlists","severity":"high","exploited":false,"published_at":"2026-05-26T21:16:39.003+00:00","url":"https://junglewise.ai/threats/cve-2026-44843-langchain-unsafe-deserialization-in-load-via-broad-object"},{"cve":"CVE-2026-40087","cvss":5.3,"epss":0.0045,"slug":"cve-2026-40087-langchain-incomplete-f-string-validation-in-prompt-templates","title":"LangChain incomplete f-string validation in prompt templates","severity":"medium","exploited":false,"published_at":"2026-04-08T21:51:32+00:00","url":"https://junglewise.ai/threats/cve-2026-40087-langchain-incomplete-f-string-validation-in-prompt-templates"},{"cve":"CVE-2026-34070","cvss":7.5,"epss":0.0121,"slug":"cve-2026-34070-langchain-langchain-core-path-traversal-in-prompt-loading","title":"LangChain langchain-core path traversal in prompt loading functions","severity":"high","exploited":false,"published_at":"2026-03-31T03:15:58.947+00:00","url":"https://junglewise.ai/threats/cve-2026-34070-langchain-langchain-core-path-traversal-in-prompt-loading"},{"cve":"CVE-2024-28088","epss":0.0174,"slug":"cve-2024-28088-langchain-directory-traversal-vulnerability","title":"PYSEC-2024-45 - LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_ch","severity":"info","exploited":false,"published_at":"2024-03-04T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-28088-langchain-directory-traversal-vulnerability"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"langchain-core (PyPI)","slug":"langchain-core","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/langchain-core/","repo_url":"https://github.com/langchain-ai/langchain","description":"LangChain Core provides the foundational abstractions and logic for the LangChain ecosystem.","url":"https://junglewise.ai/threats/technologies/langchain-core"},"most_severe":[{"cve":"CVE-2026-44843","cvss":8.2,"epss":0.0038,"slug":"cve-2026-44843-langchain-unsafe-deserialization-in-load-via-broad-object","title":"LangChain unsafe deserialization in load() via broad object allowlists","severity":"high","exploited":false,"published_at":"2026-05-26T21:16:39.003+00:00","url":"https://junglewise.ai/threats/cve-2026-44843-langchain-unsafe-deserialization-in-load-via-broad-object"},{"cve":"CVE-2026-34070","cvss":7.5,"epss":0.0121,"slug":"cve-2026-34070-langchain-langchain-core-path-traversal-in-prompt-loading","title":"LangChain langchain-core path traversal in prompt loading functions","severity":"high","exploited":false,"published_at":"2026-03-31T03:15:58.947+00:00","url":"https://junglewise.ai/threats/cve-2026-34070-langchain-langchain-core-path-traversal-in-prompt-loading"},{"cve":"CVE-2026-40087","cvss":5.3,"epss":0.0045,"slug":"cve-2026-40087-langchain-incomplete-f-string-validation-in-prompt-templates","title":"LangChain incomplete f-string validation in prompt templates","severity":"medium","exploited":false,"published_at":"2026-04-08T21:51:32+00:00","url":"https://junglewise.ai/threats/cve-2026-40087-langchain-incomplete-f-string-validation-in-prompt-templates"},{"cve":"CVE-2025-65106","cvss":4,"epss":0.0051,"slug":"cve-2025-65106-langchain-vulnerable-to-template-injection-via-attribute-access","title":"PYSEC-2026-1518 - LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:10.501462+00:00","url":"https://junglewise.ai/threats/cve-2025-65106-langchain-vulnerable-to-template-injection-via-attribute-access"},{"cve":"CVE-2025-68664","cvss":3.1,"epss":0.4293,"slug":"cve-2025-68664-langchain-serialization-injection-vulnerability-enables-secret","title":"PYSEC-2026-373 - LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:38.732432+00:00","url":"https://junglewise.ai/threats/cve-2025-68664-langchain-serialization-injection-vulnerability-enables-secret"},{"cve":"CVE-2026-26013","cvss":3.1,"epss":0.0042,"slug":"cve-2026-26013-langchain-chatopenai-server-side-request-forgery-via-image-token","title":"PYSEC-2026-2562 - LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:35.874621+00:00","url":"https://junglewise.ai/threats/cve-2026-26013-langchain-chatopenai-server-side-request-forgery-via-image-token"},{"cve":"CVE-2024-1455","cvss":3,"epss":0.0077,"slug":"cve-2024-1455-langchain-s-xmloutputparser-vulnerable-to-xml-entity-expansion","title":"PYSEC-2026-1519 - LangChain's XMLOutputParser vulnerable to XML Entity Expansion","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:36.601622+00:00","url":"https://junglewise.ai/threats/cve-2024-1455-langchain-s-xmloutputparser-vulnerable-to-xml-entity-expansion"},{"cve":"CVE-2024-10940","cvss":3,"epss":0.0039,"slug":"cve-2024-10940-langchain-core-allows-unauthorized-users-to-read-arbitrary-files","title":"PYSEC-2026-1517 - langchain-core allows unauthorized users to read arbitrary files from the host file system","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:52.475462+00:00","url":"https://junglewise.ai/threats/cve-2024-10940-langchain-core-allows-unauthorized-users-to-read-arbitrary-files"},{"cve":"CVE-2024-28088","epss":0.0174,"slug":"cve-2024-28088-langchain-directory-traversal-vulnerability","title":"PYSEC-2024-45 - LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_ch","severity":"info","exploited":false,"published_at":"2024-03-04T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-28088-langchain-directory-traversal-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}