CVE Tools

Langchain-ai

6 CVEs tracked since 2026. Since Feb 2026, none of them reached CISA KEV.

Langchain-ai CVEs per month

Feb 2026 to Feb 2026. Point at a month, or focus the strip and use the arrow keys.
Langchain-ai CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2026-0260

Products

The products that kept showing up in Langchain-ai's monthly top three, with their CVEs summed over those months.

  1. Langchainjs21 month
  2. Langchain11 month
  3. Langsmith-sdk11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Langchain-ai.

  1. CVE-2026-55253LangChain MongoDB: NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure7.7
  2. CVE-2026-55235langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication5.9
  3. CVE-2026-55236langgraph-api: Incomplete assistant authorization in LangGraph Server run creation5.9
  4. CVE-2026-72848langchain-community SitemapLoader Does Not Apply restrict_to_same_domain to Nested Sitemap Index Entries, Allowing Server-Side Request Forgery8.6
  5. CVE-2026-71433LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores5.3
  6. CVE-2026-48121@langchain/langgraph-checkpoint-mongodb: NoSQL parameter injection in MongoDBSaver allows cross-tenant state access6.7
  7. CVE-2026-59152Arbitrary server-side file read in LangSmith SDK TracingMiddleware5.0
  8. CVE-2026-14742langchain-ai langgraph Task Result Cache _cache.py _freeze weak hash3.1
  9. CVE-2026-55443LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders5.1
  10. CVE-2026-48776LangGraph SDK has unsafe URL path construction4.2
  11. CVE-2026-48775LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading6.8
  12. CVE-2026-45134LangSmith Client SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning7.1
  13. CVE-2026-44843LangChain: Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists8.2
  14. CVE-2026-41488angchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding3.1
  15. CVE-2026-41481LangChain: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass6.5

The record

Peak rank
#174 in Feb 2026
Busiest month shown
Feb 2026, 6 CVEs
Months with a KEV entry
0 since Feb 2026
Monthly snapshots
1 since 2026
Langchain-ai's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store