PT-2025-47809 · Langchain · Langchain

CVE-2025-65106

·

Published

2025-11-20

·

Updated

2026-08-31

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LangChain versions 0.3.79 and prior LangChain versions 1.0.0 through 1.0.6
Description LangChain is a framework used for building agents and applications powered by Large Language Models (LLMs). A template injection issue exists in the prompt template system, allowing attackers to access Python object internals through template syntax. This affects applications that accept untrusted template strings in ChatPromptTemplate and related prompt template classes. The issue impacts systems utilizing user-supplied templates, potentially leading to unauthorized access or code execution.
Recommendations Update to LangChain version 0.3.80 or later. Update to LangChain version 1.0.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65106
ECHO-159F-63A0-E634
GHSA-6QV9-48XG-FC7F
PYSEC-2026-1518

Affected Products

Langchain