chore(deps): update dependency langchain-core to v1 [security] - autoclosed - #164
Closed
renovate-bot wants to merge 1 commit into
Closed
Conversation
|
/gcbrun |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
>=0.1.1, <1.0.0→>=1.2.22, <1.2.23LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
CVE-2026-26013 / GHSA-2g6r-c272-w58r
More information
Details
Server-Side Request Forgery (SSRF) in ChatOpenAI Image Token Counting
Summary
The
ChatOpenAI.get_num_tokens_from_messages()method fetches arbitraryimage_urlvalues without validation when computing token counts for vision-enabled models. This allows attackers to trigger Server-Side Request Forgery (SSRF) attacks by providing malicious image URLs in user input.Severity
Low - The vulnerability allows SSRF attacks but has limited impact due to:
Impact
An attacker who can control image URLs passed to
get_num_tokens_from_messages()can:Note: This vulnerability occurs during token counting, which may happen outside of model invocation (e.g., in logging, metrics, or token budgeting flows).
Details
The vulnerable code path:
get_num_tokens_from_messages()processes messages containingimage_urlcontent blocksdetail: "low", it calls_url_to_size()to fetch the image and compute token counts_url_to_size()performshttpx.get(image_source)on any URL without validationFile:
libs/partners/openai/langchain_openai/chat_models/base.pyPatches
The vulnerability has been patched in
langchain-openai==1.1.9(requireslangchain-core==1.2.11).The patch adds:
langchain_core._security._ssrf_protection.validate_safe_url()to block:httpx.getdefault)allow_fetching_images=FalseparameterWorkarounds
If you cannot upgrade immediately:
image_urlvalues before passing messages to token counting or model invocationSeverity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
LangChain Core has Path Traversal vulnerabilites in legacy
load_promptfunctionsCVE-2026-34070 / GHSA-qh6h-p6c9-ff54
More information
Details
Summary
Multiple functions in
langchain_core.prompts.loadingread files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations toload_prompt()orload_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension checks (.txtfor templates,.json/.yamlfor examples).Note: The affected functions (
load_prompt,load_prompt_from_config, and the.save()method on prompt classes) are undocumented legacy APIs. They are superseded by thedumpd/dumps/load/loadsserialization APIs inlangchain_core.load, which do not perform filesystem reads and use an allowlist-based security model. As part of this fix, the legacy APIs have been formally deprecated and will be removed in 2.0.0.Affected component
Package:
langchain-coreFile:
langchain_core/prompts/loading.pyAffected functions:
_load_template(),_load_examples(),_load_few_shot_prompt()Severity
High
The score reflects the file-extension constraints that limit which files can be read.
Vulnerable code paths
template_path,suffix_path,prefix_path_load_template().txtexamples(when string)_load_examples().json,.yaml,.ymlexample_prompt_path_load_few_shot_prompt().json,.yaml,.ymlNone of these code paths validated the supplied path against absolute path injection or
..traversal sequences before reading from disk.Impact
An attacker who controls or influences the prompt configuration dict can read files outside the intended directory:
.txtfiles: cloud-mounted secrets (/mnt/secrets/api_key.txt),requirements.txt, internal system prompts.json/.yamlfiles: cloud credentials (~/.docker/config.json,~/.azure/accessTokens.json), Kubernetes manifests, CI/CD configs, application settingsThis is exploitable in applications that accept prompt configs from untrusted sources, including low-code AI builders and API wrappers that expose
load_prompt_from_config().Proof of concept
Mitigation
Update
langchain-coreto >= 1.2.22.The fix adds path validation that rejects absolute paths and
..traversal sequences by default. Anallow_dangerous_paths=Truekeyword argument is available onload_prompt()andload_prompt_from_config()for trusted inputs.As described above, these legacy APIs have been formally deprecated. Users should migrate to
dumpd/dumps/load/loadsfromlangchain_core.load.Credit
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
langchain-ai/langchain (langchain-core)
v1.2.18v1.2.17v1.2.16v1.2.15v1.2.14v1.2.13v1.2.12v1.2.11v1.2.10v1.2.9v1.2.8v1.2.7v1.2.6v1.2.4v1.2.3v1.2.2v1.2.1v1.2.0v1.1.3v1.1.2v1.1.1v1.1.0v1.0.7v1.0.6v1.0.5v1.0.4v1.0.3v1.0.2v1.0.0v0.3.27v0.3.26v0.3.25v0.3.24v0.3.23v0.3.22v0.3.21v0.3.20v0.3.19v0.3.18v0.1.16Compare Source
What's Changed
_load_sql_databse_chainby @B-Step62 in #19908New Contributors
Full Changelog: langchain-ai/langchain@v0.1.15...v0.1.16
v0.1.15Compare Source
What's Changed
afrom_texts&afrom_embeddingsby @crispyricepc in #20009LocalFileStoreto allow directory/file permissions to be specified by @chrispy-snps in #18857graphsupdate by @leo-gan in #19675integrations/providersupdate 10 by @leo-gan in #19970integrations/providers/unstructuredupdate by @leo-gan in #19892integrations/providersupdate 9 by @leo-gan in #19941cross_encodersflatten namespaces by @leo-gan in #20183ElasticsearchStore.BM25RetrievalStrategyby @g-votte in #20098New Contributors
Full Changelog: langchain-ai/langchain@v0.1.14...v0.1.15
v0.1.14Compare Source
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Never, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.