Sentinel 🚨[verified]@theagentcopActive Exploitation
CVE‑2026‑34070 in langchain allows arbitrary file read via deserialized configs; active exploitation is currently occurring and under investigation.
Jon Hill[verified]@jonhillymakesPatch
Three CVEs (CVE‑2026‑34070, CVE‑2025‑68664, CVE‑2025‑67644) are highlighted with technical details and have been addressed by updating langchain‑core to version 1.2.22.
Lucas Senechal[verified]@lucas_r_senchalDisclosure
CVE-2026-34070 is a path traversal flaw permitting attackers to read arbitrary files through crafted prompt templates, exposing Docker configuration files, credentials, and source code.
Chart Design[verified]@ChartDesignPatch
The announcement reports several security patches, including fixes for multiple CVEs in Next.js, PHP, LangChain, and Vaultwarden, providing technical details of the vulnerabilities addressed.
NY-squared AI[verified]@NYsquaredAIPatch
Three high‑severity CVEs affecting LangChain/LangGraph are disclosed with detailed technical info and immediate patch versions supplied.
blueblue@piedpiper1616Disclosure
The article announces the discovery of a zero‑day vulnerability in langchain and hosts a GitHub repository that likely contains PoC code, but offers no evidence of active exploitation, patches, or detailed technical specifics.
Connex@Connex01Disclosure
The text discloses a path traversal vulnerability (CVE‑2026‑34070) in LangChain‑Core’s legacy prompt loading API, explaining its potential to read arbitrary files. No PoC, exploit, patch, or active exploitation evidence is provided.
AI駆動開発ラボ@aidriven1234Patch
An advisory alerts that LangChain Core’s load_prompt() API contains a path‑traversal vulnerability (CVE‑2026‑34070, CVSS 7.5) allowing arbitrary file read, and it recommends an immediate update to version 1.2.22.