CVE-2025-68664
Description
LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions do not escape dictionaries with 'lc' keys when serializing free-form dictionaries. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization rather than plain user data. This issue has been patched in versions 0.3.81 and 1.2.5.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 75 Days)
Deserialization of Untrusted Data
DraftCommon Consequences
Applicable Platforms
LangChain Core 1.2.4 - SSTI/RCE
LangChain Core 1.2.4 - SSTI/RCE
View Exploit Code →Langchain Core by Langchain
cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:*
Langchain Core by Langchain
cpe:2.3:a:langchain:langchain_core:*:*:*:*:*:python:*:*