langchain has 9 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: langchain (6), @langchain/langgraph-checkpoint-mongodb (1), langchain_core (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 4
Weakness classes
Products
- langchain 6
- @langchain/langgraph-checkpoint-mongodb 1
- langchain_core 1
- langsmith 1
Worst active — by depth score
CVE-2026-34070High· 7.5LangChain is a framework for building agents and LLM-powered applications54CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution54CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability41CVE-2026-48121Medium· 6.7@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage37CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal36
langchain vulnerabilities
CVEs affecting langchain, newest first. Open any entry for full detail, references, and exploit status.
9 CVEsRSS
CVE-2026-48121Medium· 6.7@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage
@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and below are vulnerable to NoSQL injection: checkpoint identifiers (thread_id, checkpoint_ns, c…
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-40190Medium· 5.6LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScript/TypeScript SDK (langsmith) contains an incomplete prototype pollution fix in its internally vendored lodash set() …
CVE-2026-34070High· 7.5PoCLangChain is a framework for building agents and LLM-powered applications
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating again…
CVE-2024-3571Medium· 6.5langchain vulnerable to path traversal
langchain vulnerable to path traversal
CVE-2024-0243Low· 3.7langchain Server-Side Request Forgery vulnerability
langchain Server-Side Request Forgery vulnerability
CVE-2023-32786High· 7.5Langchain Server-Side Request Forgery vulnerability
Langchain Server-Side Request Forgery vulnerability
CVE-2023-36188Critical· 9.8langchain vulnerable to arbitrary code execution
langchain vulnerable to arbitrary code execution