CVE MEDIUM CVE-2025-6854

vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path

CVSS 4.3 langchain-chatchat View details
CVE CRITICAL CVE-2025-6853

vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend

CVSS 9.8 langchain-chatchat View details
CVE MEDIUM CVE-2024-10940

vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability

CVSS 5.3 langchain-core View details
CVE CRITICAL CVE-2024-8309

vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2024-7774

path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read

CVSS 9.1 langchain.js View details
CVE CRITICAL CVE-2024-7042

vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data

CVSS 9.8 langchain View details

vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system

CVSS 7.8 langchain View details
CVE MEDIUM CVE-2024-2965

Denial of service in langchain-community

CVSS 4.2 langchain View details

Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulnerability arises because the Web Research Retriever does not restrict

CVSS 7.7 langchain View details

versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with

CVSS 8.8 mlflow View details

langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker can leverage this

CVSS 8.8 langchain View details
CVE MEDIUM CVE-2024-1455

vulnerability in the langchain-ai/langchain repository allows for a Billion Laughs Attack, a type of XML External Entity (XXE) exploitation. By nesting multiple layers of entities within

CVSS 5.9 langchain View details
CVE CRITICAL CVE-2023-32785

Langchain SQL Injection vulnerability

CVSS 9.8 langchain View details

Langchain through 0.0.155, prompt injection allows an attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks

CVSS 7.5 langchain View details

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server

CVSS 8.8 langchain View details
CVE CRITICAL CVE-2023-39631

issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-36281

issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-38896

issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-38860

issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-36095

issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored

CVSS 9.8 langchain View details
Previous Page 3 of 4 Next