PT-2026-98873 · Unknown · Langchain4J
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:H/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
langchain4j versions prior to 1.5.3-beta11
langchain4j versions prior to 1.11.10-beta19
langchain4j versions prior to 1.18.1-beta28
Description
A flaw in the LangChain4j-agentic component allows for remote deserialization. The issue resides in the
AgenticScopeSerializer.fromJson() function within the AgenticScopeJsonSerializationIT.java file. Exploitation is difficult and requires the application to have enabled AgenticScope persistence, which is an opt-in feature, and requires the attacker to have write access to that store.Recommendations
Update to version 1.5.3-beta11.
Update to version 1.11.10-beta19.
Update to version 1.18.1-beta28.
As a temporary mitigation, disable AgenticScope persistence if it is not required.
Exploit
Fix
Deserialization of Untrusted Data
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langchain4J