Last seen March 27, 2026

LangChain Core Serialization Injection Vulnerability

Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.

Why This Matters

Publisher reporting describes a security event affecting dumpd(). BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Files is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Mar 27, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSLangChainLangChain Coredumpd()dumps()Prompt Injection

Authoritative Intelligence

CVE CVE-2025-68664 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Dec 26, 2025 05:30

    BugSkan first recorded this incident.

  • Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection - The Hacker News
    Dec 26, 2025 05:30

    thehackernews.com ยท Vulnerability

  • LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks - The Hacker News
    Mar 27, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Latest observed development
    Mar 27, 2026 05:30

    Most recent source or update associated with this incident.

Sources

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection - The Hacker News

thehackernews.com ยท Dec 26, 2025 05:30

A critical serialization injection vulnerability, CVE-2025-68664, has been discovered in LangChain Core, affecting its `dumps()` and `dumpd()` functions by failing to escape user-controlled dictionaries containing "lc" keys. This flaw allows attackers to instantiate arbitrary objects, potentially leading to secret extraction, prompt injection in LLM responses, and even arbitrary code execution through deserialization.

Open publisher source
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks - The Hacker News

thehackernews.com ยท Mar 27, 2026 05:30

Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence