Skip to content

Conversation

@bsbodden
Copy link
Contributor

@bsbodden bsbodden commented Jan 4, 2026

Addresses critical serialization injection vulnerability (CVSS 9.3) that could allow secret extraction via dumps/loads APIs.

  • Vulnerability: GHSA-c67j-w6g6-q2cm
  • Affected: langchain-core >= 1.0.0, < 1.2.5
  • Fixed in: langchain-core 1.2.5+

Addresses critical serialization injection vulnerability (CVSS 9.3)
that could allow secret extraction via dumps/loads APIs.

- Vulnerability: GHSA-c67j-w6g6-q2cm
- Affected: langchain-core >= 1.0.0, < 1.2.5
- Fixed in: langchain-core 1.2.5+
@bsbodden bsbodden merged commit a3908a9 into main Jan 4, 2026
16 checks passed
@bsbodden bsbodden deleted the bsb/security-fix-langchain-core branch January 4, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants