HomeSecurityLangChain - LangGraph: Vulnerabilities expose files and secrets

LangChain – LangGraph: Vulnerabilities expose files and secrets

Three critical security vulnerabilities in popular AI frameworks LangChain and LangGraph could expose sensitive enterprise data, including system files, environment secrets, and chat history. Cybersecurity researchers at Cyera have uncovered the vulnerabilities, affecting millions of installations worldwide.

LangChain and LangGraph vulnerabilities

LangChain and LangGraph are open-source frameworks widely used for developing applications powered by Large Language Models (LLMs) . According to statistics from the Python Package Index (PyPI) , LangChain , LangChain-Core , and LangGraph have been downloaded more than 52 million , 23 million , and 9 million times in the past week alone. LangGraph builds on the foundation of LangChain for more sophisticated and non-linear agentic workflows.

See also: LangChainGo: Critical vulnerability allows access to sensitive files

Cyera security researcher Vladimir Tokarev noted that “ each vulnerability exposes a different category of corporate data: file system files, environment secrets, and chat history .” The three vulnerabilities offer independent routes that an attacker could exploit to extract sensitive data from any corporate LangChain installation .

Analysis of critical LangChain vulnerabilities

The first vulnerability, CVE-2026-34070 with a CVSS score of 7.5, concerns a path traversal vulnerability in LangChain (specifically in “langchain_core/prompts/loading.py”). This allows access to arbitrary files without any validation via the prompt-loading API, by providing a specially crafted prompt template. Attackers can read sensitive files such as Docker configurations and other critical system files.

LangChain - LangGraph: Vulnerabilities expose files and secrets

The second and more serious vulnerability, CVE-2025-68664 with a CVSS score of 9.3, concerns deserialization of untrusted data in LangChain. This vulnerability leaks API keys and environment secretswhen passed as input a data structure that tricks the application into interpreting it as a serialized LangChain object (instead of regular user data). Cyera had shared details of this vulnerability in December 2025, giving it the name “LangGrinch”.

See also: OpenClaw AI Agent: Critical vulnerabilities allow prompt injection

The third vulnerability, CVE-2025-67644 with a CVSS score of 7.3, is an SQL injection vulnerability in the LangGraph SQLite checkpoint implementation. It allows an attacker to manipulate SQL queries via metadata filter keys and execute arbitrary SQL queries against the database, gaining access to conversation history associated with sensitive workflows.

Impacts and security fixes

Successful exploitation of these vulnerabilities could allow an attacker to read sensitive files, extract sensitive secrets via prompt injection , and gain access to chat history. According to The HackerNews, the vulnerabilities have been fixed in the following versions: CVE-2026-34070 in langchain-core ≥1.2.22, CVE-2025-68664 in langchain-core 0.3.81 and 1.2.5, and CVE-2025-67644 in langgraph-checkpoint-sqlite 3.0.1.

Article image: LangChain and LangGraph: Critical vulnerabilities expose files and secrets

The findings highlight how the artificial intelligence infrastructure is not immune to classic security vulnerabilities, potentially putting entire systems at risk.

See also: CrackArmor: 9 vulnerabilities in Linux AppArmor allow root escalation

Cyera pointed out that “LangChain , or depend on it. When there is a vulnerability in the core of LangChain, it doesn’t just affect direct users. It propagates outward through every downstream library, every wrapper, every integration that inherits the vulnerable code path.”

To protect against these threats, experts recommend immediately upgrading to patched versions, checking installations for vulnerable components, and implementing defensive measures such as login validation and sandboxing. Monitoring for prompt injection attacks and using allow-lists for deserialization are also critical security measures.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS