Critical 9.3 Severity LangChain Serialization Flaw Enables Secret Theft

A critical vulnerability (CVE-2025-68664, CVSS 9.3) was disclosed affecting the LangChain open-source LLM framework, allowing attackers to steal sensitive data and potentially trigger unintended actions via prompt injection. Due to the potential for environment variable exposure and unauthorized logic execution, immediate patching is required. The issue originates from LangChain’s (and LangChain Core’s) data serialization logic, […]

The post Critical 9.3 Severity LangChain Serialization Flaw Enables Secret Theft appeared first on Orca Security.

原始链接: https://orca.security/resources/blog/cve-2025-68664-langchain-serialization-flaw/
侵权请联系站方: [email protected]

相关推荐

换一批