CVE-2026-34070Disclosure(langchain / langchain_core)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch langchain langchain_core systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced prompt configurations to load_prompt() or load_prompt_from_config(), an attacker can read arbitrary files on the host filesystem, constrained only by file-extension checks (.txt for templates, .json/.yaml for examples). This issue has been patched in version 1.2.22.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain_core

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 11 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 12 signals
  • Disclosure: 7 classified signals
  • General: 3 classified signals
  • Peaked 7d ago at 4 mentions (2026-03-31); latest day: 1
  • 15 total mentions across 11 days

Affected systems

Vendors
Products
langchain_core

Deep dive

Activity timeline15 mentions / 11d
01234Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 4Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-17: 1Mentions · 2026-04-25: 1Mentions · 2026-05-07: 1Mentions · 2026-05-08: 1Mentions · 2026-06-20: 1PoC Mentioned / Linked · 2026-03-27: 1Active Exploitation · 2026-04-06: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-25: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 3Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-08: 1Technical Details · 2026-06-20: 103-2703-2803-3003-3104-0404-0604-1704-2505-0705-0806-20
Signal classification4 categories
Disclosure
746.7%
Patch
426.7%
General
320.0%
Active Exploitation
16.7%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-281
Disclosure1
2026-03-302
Disclosure2
2026-03-314
Disclosure1General2Patch1
2026-04-041
Patch1
2026-04-061
Active Exploitation1
2026-04-171
Disclosure1
2026-04-251
Patch1
2026-05-071
General1
2026-05-081
Patch1
2026-06-201
Disclosure1
Full discourse15 posts
  • blueblue@piedpiper1616
    Disclosure

    GitHub - Rickidevs/CVE-2026-34070: I Found a Zero-Day Vulnerability in langchain — Here’s How It Went · GitHub - https://github.com/Rickidevs/CVE-2026-34070

    Post summary

    The article announces the discovery of a zero‑day vulnerability in langchain and hosts a GitHub repository that likely contains PoC code, but offers no evidence of active exploitation, patches, or detailed technical specifics.

    020641.4K
    5.5K followersView on X
  • Sentinel 🚨@theagentcop
    Active Exploitation

    🚨 LIVE HIJACK ALERT — CVE-2026-34070. CVSS 7.5. langchain prompt loading reads user-controlled file paths without validation. attackers gain arbitrary file read access through deserialized configs. investigating. 🧵

    Post summary

    CVE‑2026‑34070 in langchain allows arbitrary file read via deserialized configs; active exploitation is currently occurring and under investigation.

    1001096
    6 followersView on X
  • Connex@Connex01
    Disclosure

    6/ 3. LangChain-Core Secret Exfiltration (CVE-2026-34070) • The Bug: Path traversal inside the legacy prompt-loading API (load_prompt()) • The Impact: If an attacker can manipulate configuration paths, they can force the server to read arbitrary local files. Making .env open

    Post summary

    The text discloses a path traversal vulnerability (CVE‑2026‑34070) in LangChain‑Core’s legacy prompt loading API, explaining its potential to read arbitrary files. No PoC, exploit, patch, or active exploitation evidence is provided.

    1000046
    102 followersView on X
  • AI駆動開発ラボ@aidriven1234
    Patch

    緊急:LangChain Coreのload_prompt()系APIにパストラバーサル(CVE-2026-34070、CVSS 7.5)。週2,300万DLライブラリの脆弱性で、APIキー・DB認証情報を含む任意ファイルが読み取り可能。マルチテナントLLMアプリを運用中なら v1.2.22 への即時アップデートを。 #AI駆動開発

    Post summary

    An advisory alerts that LangChain Core’s load_prompt() API contains a path‑traversal vulnerability (CVE‑2026‑34070, CVSS 7.5) allowing arbitrary file read, and it recommends an immediate update to version 1.2.22.

    0001084
    52 followersView on X
  • Asil Ozyildirim@AsilOzyildirim
    Disclosure

    March 2026: Three vulns in LangChain/LangGraph disclosed. CVE-2026-34070 (7.5): Arbitrary file access CVE-2025-68664 (9.3): API key leakage CVE-2025-67644 (7.3): SQL injection 9 million LangGraph downloads that week. How many organizations realized their agents compromised?

    Post summary

    Three CVEs in LangChain/LangGraph were disclosed in March 2026—covering arbitrary file access, API key leakage, and SQL injection—without mentioning active exploitation, patches, or PoC.

    10000491
    3 followersView on X
  • Jon Hill@jonhillymakes
    Patch

    The 3 CVEs: - CVE-2026-34070: Path Traversal (CVSS 7.5) - reads your filesystem - CVE-2025-68664: Deserialization Injection (CVSS 9.3 Critical) - RCE on your server - CVE-2025-67644: SQL Injection (CVSS 7.3) - exposes conversation history Patched in langchain-core 1.2.22.

    Post summary

    Three CVEs (CVE‑2026‑34070, CVE‑2025‑68664, CVE‑2025‑67644) are highlighted with technical details and have been addressed by updating langchain‑core to version 1.2.22.

    10000169
    818 followersView on X
  • bigmacd@bigmacd16684
    Disclosure

    Three vulnerabilities in LangChain & LangGraph: path traversal flaw (CVE-2026-34070, CVSS 7.5) exposed files, deserialization bug (CVE-2025-68664, CVSS 9.3) leaked API keys. #security #LangChain #LangGraph

    Post summary

    The post announces two CVEs for LangChain & LangGraph, detailing a path traversal flaw that exposes files and a deserialization bug that leaks API keys, each accompanied by CVSS scores.

    10000231
    6 followersView on X
  • Lucas Senechal@lucas_r_senchal
    Disclosure

    CVE-2026-34070: Path traversal via prompt templates. Load a crafted prompt, read arbitrary files. Docker configs, credentials, source code — all accessible.

    Post summary

    CVE-2026-34070 is a path traversal flaw permitting attackers to read arbitrary files through crafted prompt templates, exposing Docker configuration files, credentials, and source code.

    1000025
    192 followersView on X
  • Chart Design@ChartDesign
    Patch

    プログラミングニュース 2026年第19週を公開しました。 今週のハイライト: **セキュリティ(要対応)** - Next.js 16.2.5 — 高危険度CVE 6件修正(DoS・SSRFなど) - PHP 8.2〜8.5 全系統 セキュリティリリース(CVE 8件) - LangChain CVE-2026-34070 パストラバーサル修正 - Vaultwarden 1.36.0 — SSO CSRF修正 **言語** - Node.js 26.0.0 メジャーリリース — Temporal API がデフォルト有効に - Python 3.15.0 beta 1 / 3.14.5 RC リリース - Rust — Outreachy 2026 参加・nvptx64ターゲット要件引き上げ - Kotlin 2.4.0-Beta2 / LinkedIn Learning認定資格リリース **フレームワーク** - React 19.2.6/19.1.7/19.0.6 — Server Components型強化 - React Native 0.86.0-rc.0 / 0.85.3 - Vue.js 3.6.0-beta.11 / 3.5.34 - Laravel v13.8.0 **OSS注目** - Ollama v0.23.0 — Claude Desktop サポート追加 - Outline v1.7.1 — MCP強化(削除ツール追加) - Misskey 2026.5.1 / Strapi v5.45.0 / n8n 2.19.5 **ライブラリ** - axios v1.16.0 — QUERY メソッド対応 - Tokio 1.52.2 / Zod v4.4.3 / Tauri v2.11.1 動画はこちら → https://youtu.be/atbUFUIuhWY #プログラミング #JavaScript #NodeJS #PHP #Rust #NextJS #OSS #個人開発

    Post summary

    The announcement reports several security patches, including fixes for multiple CVEs in Next.js, PHP, LangChain, and Vaultwarden, providing technical details of the vulnerabilities addressed.

    00000184
    22 followersView on X
  • AIDailyGems@AIDailyGems
    General

    CVE-2026-34070 in `langchain-core` makes a good case for vendoring specific LLM client code instead of pulling in large frameworks. Less surface area, fewer surprises. https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.86 https://t.co/D2fusMacvR

    Post summary

    The tweet notes CVE‑2026‑34070 in langchain‑core and links to a GitHub release, but provides no technical or exploit details.

    0000053
    275 followersView on X
  • NY-squared AI@NYsquaredAI
    Patch

    3 serious CVEs just dropped for LangChain + LangGraph: - CVE-2025-68664 (CVSS 9.3): API keys & env secrets leak via unsafe deserialization - CVE-2026-34070 (CVSS 7.5): Path traversal -- arbitrary file read - CVE-2025-67644 (CVSS 7.3): SQL injection into conversation history 60M downloads/week. The core of your AI stack is now an attack surface. Patch now: v1.2.22+ / v0.3.81+ / langgraph-checkpoint-sqlite v3.0.1+ #AISecurity #LangChain #LLMSecurity

    Post summary

    Three high‑severity CVEs affecting LangChain/LangGraph are disclosed with detailed technical info and immediate patch versions supplied.

    00000415
    29 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-34070 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-34070 #CVE-2026-34070 #CVE #High #CyberSecurity #InfoSec https://t.co/secVhVb56x

    Post summary

    The tweet announces CVE‑2026‑34070 with a high severity rating but provides no technical, exploit, or mitigation details.

    0000026
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34070 LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files fr… https://www.cve.org/CVERecord?id=CVE-2026-34070

    Post summary

    The post references CVE-2026-34070 with a vague description of functions that read files, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000083
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34070 - LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions Intel Report: https://ift.tt/jfizX1W

    Post summary

    The alert announces a new CVE-2026-34070 affecting LangChain Core, describing Path Traversal vulnerabilities in legacy load_prompt functions; it lacks evidence of PoC, exploit code, or active attacks, and no patches or workarounds are provided.

    0000037
    281 followersView on X
  • Total Compliance Tracking@GetTCT
    Disclosure

    Three new vulnerabilities (including CVE-2026-34070) have been disclosed that expose local files, secrets, and backend databases via SSRF . The models aren't the only target—the frameworks connecting them to your data are the soft underbelly. Details: https://hubs.ly/Q048SgSL0

    Post summary

    The post announces the disclosure of three SSRF vulnerabilities, including CVE-2026-34070, exposing local files, secrets, and database information, but provides no PoC, exploitation details, patch information, or debunking claims.

    0000027
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain_core-python-

Explore more