{"schema_version":1,"title":"langchain (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 27 vulnerabilities in langchain (PyPI): 0 in the last 7 days and 6 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2024-2965, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/langchain","json_url":"https://junglewise.ai/threats/technologies/langchain.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/langchain","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":27,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":6,"last_365_days":11},"latest":[{"cve":"CVE-2024-2965","cvss":3.1,"epss":0.003,"slug":"cve-2024-2965-langchain-sitemaploader-denial-of-service-via-infinite-recursion","title":"PYSEC-2026-2561 - Denial of service in langchain-community","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.210054+00:00","url":"https://junglewise.ai/threats/cve-2024-2965-langchain-sitemaploader-denial-of-service-via-infinite-recursion"},{"cve":"CVE-2024-8309","cvss":3.1,"epss":0.1374,"slug":"cve-2024-8309-langchain-sql-injection-vulnerability","title":"PYSEC-2026-1507 - Langchain SQL Injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:43.617965+00:00","url":"https://junglewise.ai/threats/cve-2024-8309-langchain-sql-injection-vulnerability"},{"cve":"CVE-2024-5998","cvss":3.1,"epss":0.0036,"slug":"cve-2024-5998-langchain-pickle-deserialization-of-untrusted-data","title":"PYSEC-2026-1514 - LangChain pickle deserialization of untrusted data","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:41.419579+00:00","url":"https://junglewise.ai/threats/cve-2024-5998-langchain-pickle-deserialization-of-untrusted-data"},{"cve":"CVE-2024-3571","cvss":3,"epss":0.0187,"slug":"cve-2024-3571-langchain-vulnerable-to-path-traversal","title":"PYSEC-2026-1510 - langchain vulnerable to path traversal","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:39.44871+00:00","url":"https://junglewise.ai/threats/cve-2024-3571-langchain-vulnerable-to-path-traversal"},{"cve":"CVE-2024-0243","cvss":3.1,"epss":0.0052,"slug":"cve-2024-0243-langchain-server-side-request-forgery-vulnerability","title":"PYSEC-2026-1509 - langchain Server-Side Request Forgery vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:32.931836+00:00","url":"https://junglewise.ai/threats/cve-2024-0243-langchain-server-side-request-forgery-vulnerability"},{"cve":"CVE-2023-32786","cvss":3.1,"epss":0.007,"slug":"cve-2023-32786-langchain-server-side-request-forgery-vulnerability","title":"PYSEC-2026-1508 - Langchain Server-Side Request Forgery vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:26.029662+00:00","url":"https://junglewise.ai/threats/cve-2023-32786-langchain-server-side-request-forgery-vulnerability"},{"cve":"CVE-2023-32785","cvss":3.1,"slug":"cve-2023-32785-langchain-sql-injection-vulnerability","title":"PYSEC-2026-372 - Langchain SQL Injection vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:43.657008+00:00","url":"https://junglewise.ai/threats/cve-2023-32785-langchain-sql-injection-vulnerability"},{"cve":"CVE-2026-55443","cvss":5.1,"epss":0.0021,"slug":"cve-2026-55443-langchain-path-traversal-and-sandbox-escape-in-file-search","title":"LangChain path traversal and sandbox escape in file-search middleware and loaders","severity":"medium","exploited":false,"published_at":"2026-06-22T19:17:21.537+00:00","url":"https://junglewise.ai/threats/cve-2026-55443-langchain-path-traversal-and-sandbox-escape-in-file-search"},{"cvss":5.1,"slug":"langchain-path-traversal-and-sandbox-escape-in-file-search-and-loaders-6c83f652","title":"LangChain path traversal and sandbox escape in file-search and loaders","severity":"medium","exploited":false,"published_at":"2026-06-16T15:03:14+00:00","url":"https://junglewise.ai/threats/langchain-path-traversal-and-sandbox-escape-in-file-search-and-loaders-6c83f652"},{"cve":"CVE-2026-45134","cvss":7.1,"epss":0.0034,"slug":"cve-2026-45134-langchain-langsmith-sdk-untrusted-deserialization-in-prompt-pull","title":"LangChain LangSmith SDK untrusted deserialization in prompt pull methods","severity":"high","exploited":false,"published_at":"2026-05-27T20:16:38.697+00:00","url":"https://junglewise.ai/threats/cve-2026-45134-langchain-langsmith-sdk-untrusted-deserialization-in-prompt-pull"},{"cve":"CVE-2024-58340","cvss":7.5,"epss":0.0047,"slug":"cve-2024-58340-langchain-redos-in-mrkloutputparser","title":"LangChain ReDoS in MRKLOutputParser","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.78+00:00","url":"https://junglewise.ai/threats/cve-2024-58340-langchain-redos-in-mrkloutputparser"},{"cvss":3.1,"slug":"pysec-2024-111-a-path-traversal-vulnerability-exists-in-the-getfullpath-7b8fc815","title":"PYSEC-2024-111 - A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attac","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2024-111-a-path-traversal-vulnerability-exists-in-the-getfullpath-7b8fc815"},{"cvss":3.1,"slug":"pysec-2024-114-a-vulnerability-in-the-graphcypherqachain-class-of-eb1e3572","title":"PYSEC-2024-114 - A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for promp","severity":"low","exploited":false,"published_at":"2024-10-29T13:15:00+00:00","url":"https://junglewise.ai/threats/pysec-2024-114-a-vulnerability-in-the-graphcypherqachain-class-of-eb1e3572"},{"cve":"CVE-2024-28088","epss":0.0174,"slug":"cve-2024-28088-langchain-directory-traversal-vulnerability","title":"PYSEC-2024-45 - LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_ch","severity":"info","exploited":false,"published_at":"2024-03-04T00:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-28088-langchain-directory-traversal-vulnerability"},{"cve":"CVE-2023-46229","cvss":3.1,"epss":0.4471,"slug":"cve-2023-46229-langchain-server-side-request-forgery-vulnerability","title":"PYSEC-2023-205 - LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an","severity":"low","exploited":false,"published_at":"2023-10-19T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-46229-langchain-server-side-request-forgery-vulnerability"},{"cve":"CVE-2023-39631","cvss":3.1,"epss":0.016,"slug":"cve-2023-39631-langchain-vulnerable-to-arbitrary-code-execution-via-the-evaluate","title":"PYSEC-2023-162 - An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr libr","severity":"low","exploited":false,"published_at":"2023-09-01T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-39631-langchain-vulnerable-to-arbitrary-code-execution-via-the-evaluate"},{"cve":"CVE-2023-36281","cvss":3.1,"epss":0.0344,"slug":"cve-2023-36281-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-151 - An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the load_prompt parameter.","severity":"low","exploited":false,"published_at":"2023-08-22T19:16:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36281-langchain-vulnerable-to-arbitrary-code-execution"},{"cve":"CVE-2023-39659","cvss":3.1,"epss":0.0153,"slug":"cve-2023-39659-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-147 - An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the Pytho","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-39659-langchain-vulnerable-to-arbitrary-code-execution"},{"cve":"CVE-2023-38860","cvss":3.1,"epss":0.0142,"slug":"cve-2023-38860-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-145 - An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38860-langchain-vulnerable-to-arbitrary-code-execution"},{"cve":"CVE-2023-38896","cvss":3.1,"epss":0.0184,"slug":"cve-2023-38896-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-146 - An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and fr","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38896-langchain-vulnerable-to-arbitrary-code-execution"},{"cve":"CVE-2023-36095","cvss":3.1,"epss":0.0117,"slug":"cve-2023-36095-langchain-code-injection-vulnerability","title":"PYSEC-2023-138 - An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affec","severity":"low","exploited":false,"published_at":"2023-08-05T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36095-langchain-code-injection-vulnerability"},{"cve":"CVE-2023-36188","cvss":9.8,"epss":0.019,"slug":"cve-2023-36188-langchain-remote-code-execution-in-palchain-python-exec-method","title":"LangChain remote code execution in PALChain Python exec method","severity":"critical","exploited":false,"published_at":"2023-07-06T15:30:33+00:00","url":"https://junglewise.ai/threats/cve-2023-36188-langchain-remote-code-execution-in-palchain-python-exec-method"},{"cve":"CVE-2023-36189","cvss":3.1,"epss":0.0125,"slug":"cve-2023-36189-langchain-sql-injection-vulnerability","title":"PYSEC-2023-110 - SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain componen","severity":"low","exploited":false,"published_at":"2023-07-06T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36189-langchain-sql-injection-vulnerability"},{"cve":"CVE-2023-36258","cvss":3.1,"epss":0.0107,"slug":"cve-2023-36258-langchain-arbitrary-code-execution-in-palchain","title":"PYSEC-2023-98 - An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method.","severity":"low","exploited":false,"published_at":"2023-07-03T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36258-langchain-arbitrary-code-execution-in-palchain"},{"cve":"CVE-2023-34541","cvss":3.1,"epss":0.0094,"slug":"cve-2023-34541-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-92 - Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.","severity":"low","exploited":false,"published_at":"2023-06-20T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-34541-langchain-vulnerable-to-arbitrary-code-execution"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"langchain (PyPI)","slug":"langchain","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.langchain.com/","repo_url":"https://github.com/langchain-ai/langchain","description":"A framework for developing applications powered by large language models.","url":"https://junglewise.ai/threats/technologies/langchain"},"most_severe":[{"cve":"CVE-2023-36188","cvss":9.8,"epss":0.019,"slug":"cve-2023-36188-langchain-remote-code-execution-in-palchain-python-exec-method","title":"LangChain remote code execution in PALChain Python exec method","severity":"critical","exploited":false,"published_at":"2023-07-06T15:30:33+00:00","url":"https://junglewise.ai/threats/cve-2023-36188-langchain-remote-code-execution-in-palchain-python-exec-method"},{"cve":"CVE-2024-58340","cvss":7.5,"epss":0.0047,"slug":"cve-2024-58340-langchain-redos-in-mrkloutputparser","title":"LangChain ReDoS in MRKLOutputParser","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.78+00:00","url":"https://junglewise.ai/threats/cve-2024-58340-langchain-redos-in-mrkloutputparser"},{"cve":"CVE-2026-45134","cvss":7.1,"epss":0.0034,"slug":"cve-2026-45134-langchain-langsmith-sdk-untrusted-deserialization-in-prompt-pull","title":"LangChain LangSmith SDK untrusted deserialization in prompt pull methods","severity":"high","exploited":false,"published_at":"2026-05-27T20:16:38.697+00:00","url":"https://junglewise.ai/threats/cve-2026-45134-langchain-langsmith-sdk-untrusted-deserialization-in-prompt-pull"},{"cve":"CVE-2026-55443","cvss":5.1,"epss":0.0021,"slug":"cve-2026-55443-langchain-path-traversal-and-sandbox-escape-in-file-search","title":"LangChain path traversal and sandbox escape in file-search middleware and loaders","severity":"medium","exploited":false,"published_at":"2026-06-22T19:17:21.537+00:00","url":"https://junglewise.ai/threats/cve-2026-55443-langchain-path-traversal-and-sandbox-escape-in-file-search"},{"cvss":5.1,"slug":"langchain-path-traversal-and-sandbox-escape-in-file-search-and-loaders-6c83f652","title":"LangChain path traversal and sandbox escape in file-search and loaders","severity":"medium","exploited":false,"published_at":"2026-06-16T15:03:14+00:00","url":"https://junglewise.ai/threats/langchain-path-traversal-and-sandbox-escape-in-file-search-and-loaders-6c83f652"},{"cve":"CVE-2023-46229","cvss":3.1,"epss":0.4471,"slug":"cve-2023-46229-langchain-server-side-request-forgery-vulnerability","title":"PYSEC-2023-205 - LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an","severity":"low","exploited":false,"published_at":"2023-10-19T05:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-46229-langchain-server-side-request-forgery-vulnerability"},{"cve":"CVE-2023-29374","cvss":3.1,"epss":0.3965,"slug":"cve-2023-29374-langchain-vulnerable-to-code-injection","title":"PYSEC-2023-18 - In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec met","severity":"low","exploited":false,"published_at":"2023-04-05T02:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-29374-langchain-vulnerable-to-code-injection"},{"cve":"CVE-2024-8309","cvss":3.1,"epss":0.1374,"slug":"cve-2024-8309-langchain-sql-injection-vulnerability","title":"PYSEC-2026-1507 - Langchain SQL Injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:43.617965+00:00","url":"https://junglewise.ai/threats/cve-2024-8309-langchain-sql-injection-vulnerability"},{"cve":"CVE-2023-36281","cvss":3.1,"epss":0.0344,"slug":"cve-2023-36281-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-151 - An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the load_prompt parameter.","severity":"low","exploited":false,"published_at":"2023-08-22T19:16:00+00:00","url":"https://junglewise.ai/threats/cve-2023-36281-langchain-vulnerable-to-arbitrary-code-execution"},{"cve":"CVE-2023-38896","cvss":3.1,"epss":0.0184,"slug":"cve-2023-38896-langchain-vulnerable-to-arbitrary-code-execution","title":"PYSEC-2023-146 - An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and fr","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38896-langchain-vulnerable-to-arbitrary-code-execution"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}