CVE-2024-3571Medium· 6.5▾ Sunlitlangchain vulnerable to path traversal
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.9%
1.9% → 1.9%
langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this vulnerability to read or write files anywhere on the filesystem, potentially leading to information disclosure or remote code execution. The issue lies in the handling of file paths in the mset and mget methods, where user-supplied input is not adequately sanitized, allowing directory traversal sequences to reach unintended directories.
langchain < 0.0.353Upgrade to a patched release:
langchain 0.0.353Connected by shared product, vendor, weakness, or advisory.
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
CVE-2026-34070High· 7.5LangChain is a framework for building agents and LLM-powered applications
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders