langchain-core has 6 CVEs on record between 2024 and 2026. The median CVSS is 5.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- langchain-core 6
Worst active — by depth score
CVE-2026-44843High· 8.2LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists45CVE-2025-65106HighLangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates41CVE-2024-1455Medium· 5.9LangChain's XMLOutputParser vulnerable to XML Entity Expansion33CVE-2026-40087Medium· 5.3LangChain has incomplete f-string validation in prompt templates29CVE-2024-10940Medium· 5.3langchain-core allows unauthorized users to read arbitrary files from the host file system29
langchain-core vulnerabilities
CVEs affecting langchain-core, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-44843High· 8.2LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
CVE-2026-40087Medium· 5.3LangChain has incomplete f-string validation in prompt templates
LangChain has incomplete f-string validation in prompt templates
CVE-2026-26013Low· 3.7LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2025-65106HighLangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
CVE-2024-10940Medium· 5.3langchain-core allows unauthorized users to read arbitrary files from the host file system
langchain-core allows unauthorized users to read arbitrary files from the host file system
CVE-2024-1455Medium· 5.9LangChain's XMLOutputParser vulnerable to XML Entity Expansion
LangChain's XMLOutputParser vulnerable to XML Entity Expansion