Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34070

Опубликовано: 31 мар. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension checks (.txt for templates, .json/.yaml for examples). This issue has been patched in version 1.2.22.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:*
Версия до 1.2.22 (исключая)

EPSS

Процентиль: 65%
0.01204
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension checks (.txt for templates, .json/.yaml for examples). This issue has been patched in version 1.2.22.

CVSS3: 7.5
github
5 месяцев назад

LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions

EPSS

Процентиль: 65%
0.01204
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-22