langchain-community vulnerabilities
CVEs whose affected-version data names the langchain-community package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2025-6984High· 7.5Langchain Community Vulnerable to XML External Entity (XXE) Attacks
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
▾ Twilightlangchain-community · langchain-communityEPSS 1.6%via OSV
CVE-2024-8309Medium· 4.9PoCLangchain SQL Injection vulnerability
Langchain SQL Injection vulnerability
▾ Twilightlangchain-community · langchain-communityEPSS 14%via OSV
CVE-2024-5998Medium· 5.2LangChain pickle deserialization of untrusted data
LangChain pickle deserialization of untrusted data
▾ Sunlitlangchain-community · langchain-communityEPSS 0.36%via OSV
CVE-2024-2965Medium· 4.2Denial of service in langchain-community
Denial of service in langchain-community
▾ Sunlitlangchain-community · langchain-communityEPSS 0.30%via OSV
CVE-2024-3095Medium· 4.8Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever
▾ Sunlitlangchain-community · langchain-communityEPSS 0.69%via OSV