PT-2026-98873 · Unknown · Langchain4J

·

CVE-2026-97869

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v2.0

4.3

Medium

VectorAV:N/AC:H/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions langchain4j versions prior to 1.5.3-beta11 langchain4j versions prior to 1.11.10-beta19 langchain4j versions prior to 1.18.1-beta28
Description A flaw in the LangChain4j-agentic component allows for remote deserialization. The issue resides in the AgenticScopeSerializer.fromJson() function within the AgenticScopeJsonSerializationIT.java file. Exploitation is difficult and requires the application to have enabled AgenticScope persistence, which is an opt-in feature, and requires the attacker to have write access to that store.
Recommendations Update to version 1.5.3-beta11. Update to version 1.11.10-beta19. Update to version 1.18.1-beta28. As a temporary mitigation, disable AgenticScope persistence if it is not required.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97869
GHSA-GMWR-7WMF-MRJM

Affected Products

Langchain4J