VulnSea

langchain has 9 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: langchain (6), @langchain/langgraph-checkpoint-mongodb (1), langchain_core (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
1 prev 4

Products

  • langchain 6
  • @langchain/langgraph-checkpoint-mongodb 1
  • langchain_core 1
  • langsmith 1
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

langchain vulnerabilities

CVEs affecting langchain, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-48121Medium· 6.7
1mo ago

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, c…

Sunlitlangchain · @langchain/langgraph-checkpoint-mongodbEPSS 0.23%via NVD
CVE-2026-55443Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

Sunlitlangchain · langchainEPSS 0.21%via OSV
GHSA-gr75-jv2w-4656Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

Sunlitlangchain · langchainvia GHSA
CVE-2026-40190Medium· 5.6
5mo ago

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() …

Sunlitlangchain · langsmithEPSS 0.31%via NVD
CVE-2026-34070High· 7.5PoC
5mo ago

LangChain is a framework for building agents and LLM-powered applications

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…

Midnightlangchain · langchain_coreEPSS 1.4%via NVD
CVE-2024-3571Medium· 6.5
2y ago

langchain vulnerable to path traversal

langchain vulnerable to path traversal

Sunlitlangchain · langchainEPSS 1.9%via OSV
CVE-2024-0243Low· 3.7
2y ago

langchain Server-Side Request Forgery vulnerability

langchain Server-Side Request Forgery vulnerability

Sunlitlangchain · langchainEPSS 0.52%via OSV
CVE-2023-32786High· 7.5
2y ago

Langchain Server-Side Request Forgery vulnerability

Langchain Server-Side Request Forgery vulnerability

Twilightlangchain · langchainEPSS 0.70%via OSV
CVE-2023-36188Critical· 9.8
3y ago

langchain vulnerable to arbitrary code execution

langchain vulnerable to arbitrary code execution

Midnightlangchain · langchainEPSS 1.9%via OSV
langchain vulnerabilities (CVEs) · VulnSea