PT-2024-22256 · Langchain · Langchain

Pinkdraconian

·

Published

2024-03-03

·

Updated

2025-06-13

·

CVE-2024-28088

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions LangChain versions 0.1.10 and earlier
Description The issue allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution.
Recommendations For LangChain versions 0.1.10 and earlier, update to version 0.1.29 or later of langchain-core to resolve the issue. As a temporary workaround, consider restricting the use of the load chain call to minimize the risk of exploitation. Avoid using the path parameter in the affected load chain call until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-28088
GHSA-H59X-P739-982C
PYSEC-2024-43
PYSEC-2024-45

Affected Products

Langchain