Last seen March 27, 2026

CVE-2025-68664 Security Incident affecting AI

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include < 3.0.1.

Technical Severity
Medium severity
Lifecycle Status

DEVELOPING

What Happened

Evidence indicates that the affected technology is affected by a security issue. Reported affected versions include < 3.0.1.

Why This Matters

Current evidence identifies a security issue involving Critical LangChain Core, but does not yet support a more specific impact claim.

Recommended Action

Upgrade langgraph-checkpoint-sqlite to 3.0.1 or later. Identify deployments of Critical LangChain Core matching the evidenced affected versions: < 3.0.1.

Exposure

Recommended Response
First Seen

Dec 26, 2025 05:30

Last Seen

Mar 27, 2026 05:30

Exploitation status: UNKNOWN

Affected versions: < 3.0.1

Primary entities:

Prompt Injection Remote Code Execution CVE-2025-68664 CVE-2025-67644 CVE-2026-34070 langchain-core

Authoritative Intelligence

CVE CVE-2025-68664, CVE-2025-67644, CVE-2026-34070 Incident identifier
NVD CVSS 7.5 HIGH NVD
FIRST EPSS 0.023 81.5 pct
Fixed Version 3.0.1, 1.2.5, 0.3.81 +1 Provider-backed
GHSA GHSA-9RWJ-6RC7-P77C, GHSA-C67J-W6G6-Q2CM +1 GitHub advisory alias
CWE CWE-22, CWE-89, CWE-502 Weakness classification

Provider evidence: NVD, GitHub Advisory, OSV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Dec 26, 2025 05:30

    BugSkan first recorded this incident.

  • Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection - The Hacker News
    Dec 26, 2025 05:30

    thehackernews.com ยท Vulnerability

  • LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks - The Hacker News
    Mar 27, 2026 05:30

    thehackernews.com ยท Vulnerability

  • Latest observed development
    Mar 27, 2026 05:30

    Most recent source or update associated with this incident.

  • Material change
    Aug 18, 2026 14:07

    recommended action updated

  • Material change
    Aug 18, 2026 14:07

    why it matters updated

Sources

Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection - The Hacker News

thehackernews.com ยท Dec 26, 2025 05:30

A critical serialization injection vulnerability, CVE-2025-68664, has been discovered in LangChain Core, affecting its `dumps()` and `dumpd()` functions by failing to escape user-controlled dictionaries containing "lc" keys. This flaw allows attackers to instantiate arbitrary objects, potentially leading to secret extraction, prompt injection in LLM responses, and even arbitrary code execution through deserialization.

Open publisher source
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks - The Hacker News

thehackernews.com ยท Mar 27, 2026 05:30

Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

โ† Back to incident intelligence