Known Vulnerabilities for Langchain by Langchain-ai
Listed below are 9 of the newest known vulnerabilities associated with "Langchain" by "Langchain-ai".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55443 json | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-48121 json | @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage.... | Not Provided | 2026-08-04 | 2026-08-04 |
| CVE-2026-41481 json | LangChain is a framework for building agents and LLM-powered applications. Prior to langchain-text-splitters 1.1.2, HTMLHead... | Not Provided | 2026-04-24 | 2026-07-15 |
| CVE-2026-34070 json | LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in lan... | Not Provided | 2026-03-31 | 2026-08-25 |
| CVE-2026-14742 json | A vulnerability was determined in langchain-ai langgraph up to 1.2.4. The affected element is the function _freeze of the fil... | Not Provided | 2026-07-05 | 2026-07-06 |
| CVE-2026-14630 json | A vulnerability has been found in ForceInjection AI-fundermentals 2.0/3.0. Affected by this vulnerability is the function get... | Not Provided | 2026-07-04 | 2026-07-06 |
| CVE-2025-45150 json | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive file... | Not Provided | 2025-08-01 | 2026-07-05 |
| CVE-2024-58340 json | LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKL... | Not Provided | 2026-01-12 | 2026-07-14 |
| CVE-2023-36095 json | An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the ... | Not Provided | 2023-08-05 | 2026-07-09 |