LangChain Core Serialization Injection Vulnerability
Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.
What Happened
Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.
Why This Matters
Publisher reporting describes a security event affecting dumpd(). BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Files is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Mar 27, 2026 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2025-68664: 3 public repository references found.
Possible public PoC reference
A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only
3 stars ยท Python
Open repositoryPublic GitHub reference
Technical analysis of the LangChain serialization injection vulnerability CVE-2025-68664.
0 stars
Open repositoryPublic GitHub reference
GitHub repository for an AI tooling project
0 stars
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Dec 26, 2025 05:30BugSkan first recorded this incident.
-
Critical LangChain Core Vulnerability Exposes Secrets via Serialization Injection - The Hacker News
Dec 26, 2025 05:30thehackernews.com ยท Vulnerability
-
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks - The Hacker News
Mar 27, 2026 05:30thehackernews.com ยท Vulnerability
-
Latest observed development
Mar 27, 2026 05:30Most recent source or update associated with this incident.
Sources
thehackernews.com ยท Dec 26, 2025 05:30
A critical serialization injection vulnerability, CVE-2025-68664, has been discovered in LangChain Core, affecting its `dumps()` and `dumpd()` functions by failing to escape user-controlled dictionaries containing "lc" keys. This flaw allows attackers to instantiate arbitrary objects, potentially leading to secret extraction, prompt injection in LLM responses, and even arbitrary code execution through deserialization.
Open publisher sourcethehackernews.com ยท Mar 27, 2026 05:30
Three critical vulnerabilities (CVE-2026-34070, CVE-2025-68664, CVE-2025-67644) have been discovered in LangChain and LangGraph, widely used AI frameworks for building LLM applications. These flaws include path traversal, deserialization of untrusted data, and SQL injection, allowing attackers to access arbitrary filesystem files, leak environment secrets, and execute arbitrary SQL queries against conversation history databases.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.