← Back

CVE-2026-44843

nvd nist
Published: May 26, 2026Modified: Jul 24, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Exploitability: 3.9 / Impact: 4.2
Source: security-advisories@github.com (Secondary)

Description

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments. This vulnerability is fixed in 0.3.85 and 1.3.3.

Affected (2)

Products: Langchain: Langchain
1 product
Langchain
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Langchain
Before 0.3.85
From 1.0.0 to 1.3.3

References (1)

Source: security-advisories@github.com
MitigationVendor Advisory

Timeline

No history available yet.