CVE-2026-44843Disclosure(langchain / langchain)

MEDIUMCVSS 8.2 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch langchain langchain systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() with allowed_objects="all". This does not enable arbitrary Python object deserialization, but it does allow any trusted LangChain-serializable object to be revived, which is broader than these runtime paths require. As a result, attacker-supplied LangChain serialized constructor dictionaries may cause trusted runtime paths to instantiate classes with untrusted constructor arguments. This vulnerability is fixed in 0.3.85 and 1.3.3.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langchain

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-06-17); latest day: 1
  • 13 total mentions across 7 days

Affected systems

Vendors
Products
langchain

Deep dive

Activity timeline13 mentions / 7d
01234Mentions · 2026-05-10: 2Mentions · 2026-05-11: 2Mentions · 2026-05-13: 2Mentions · 2026-05-18: 1Mentions · 2026-05-27: 1Mentions · 2026-06-17: 4Mentions · 2026-06-19: 1PoC Mentioned / Linked · 2026-05-11: 1Active Exploitation · 2026-05-13: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-17: 305-1005-1105-1305-1805-2706-1706-19
Signal classification3 categories
Disclosure
969.2%
General
323.1%
Active Exploitation
17.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-102
Disclosure1General1
2026-05-112
Disclosure1General1
2026-05-132
Active Exploitation1Disclosure1
2026-05-181
Disclosure1
2026-05-271
Disclosure1
2026-06-174
Disclosure4
2026-06-191
General1
Full discourse13 posts
  • Nicolas Krassas@Dinosn
    General

    CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! https://medium.com/@dewankpant/cve-2026-44843-one-chat-message-steals-your-credentials-then-it-gets-worse-264146623aec

    Post summary

    A Medium article link referencing CVE-2026-44843 is provided, but the text offers no additional details, PoC, exploit, or mitigation information.

    0301342.2K
    158.6K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    مين يستخدم LangChain ؟ اليوم تم الاعلان عن ثغره عالية الخطوره CVE-2026-44843 | 🟠 HIGH 8.2 حدث الى الاصدار 0.3.85 او 1.3.3. https://t.co/37PPveTdaH

    Post summary

    The tweet announces CVE-2026-44843 as a high‑severity vulnerability for LangChain and recommends upgrading to version 0.3.85 or 1.3.3 as a mitigation.

    0119812.8K
    50.0K followersView on X
  • Damilola Ashiedu | Pretty Cyber Girl 💻💡@prettycyb3rgirl
    Disclosure

    A new CVE dropped for LangChain Core (CVE-2026-44843) — unsafe deserialization via overly broad load() allowlists. CVSS 7.5 HIGH. Blast radius is not just LangChain. Wave 1: LangChain, LC Community, LC MCP Adapters Wave 2: MLflow, Langflow, Flowise Wave 3: LiteLLM, Weights & Biases Wave 4: smolagents That is 9 packages in total that could be affected. This is exactly why supply chain visibility matters. https://ai-supply-chain-observatory.vercel.app/ already has this updated. Btw, I need more suggestions on how this can help organizations better, so I can implement everything I have in mind at once. Thank youuu

    Post summary

    A newly disclosed CVE-2026-44843 affecting LangChain Core and related packages is highlighted, noting an unsafe deserialization flaw with a CVSS of 7.5, but provides no exploit or workaround details.

    05070503
    4.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-44843: Single chat message triggers unauthenticated credential exfiltration from LangChain applications via malicious object deserialization in tracer component. CVSS not specified, but enables full workspace takeover. Key technical details: • Exploits broad object deserialization in langchain-core tracer paths (_exit_history, astream_log, astream_events v1) using load(run.inputs, allowed_objects="all") • Attack payload: JSON dict with HubRunnable constructor that omits api_key, forcing fallback to LANGSMITH_API_KEY environment variable • Vulnerable paths: RunnableWithMessageHistory, astream_log(), astream_events(version="v1") in public LangServe endpoints • 94 registered serializable classes were potential gadgets for constructor-based side effects Attack methodology: • Attacker sends structured chat message mimicking LangChain serialized object format • Framework preserves dict structure in run.inputs without sanitization • Tracer calls load() during object revival, instantiating HubRunnable • Constructor triggers LangSmith client creation with attacker-controlled api_url • Client reads production API key from environment, sends in x-api-key header to attacker URL DFIR artifacts: • Outbound HTTP requests to suspicious domains with x-api-key headers containing "lsv2_pt_" tokens • Process execution of langsmith-py client with network connections during chat processing #DFIR_Radar

    Post summary

    DFIR evidence confirms CVE‑2026‑44843 is being actively exploited in the wild through crafted LangChain serialized objects, enabling credential exfiltration and potential full workspace takeover. No mitigation or patch is disclosed.

    10051471
    1.8K followersView on X
  • CyStack@CyStackSecurity
    Disclosure

    📣 ADVISORY: Researcher phucnd from CyStack discovered an Unsafe Deserialization vulnerability in LangChain CVE-2026-44843 (CVSS 8.2). This affected: langchain-core <=0.3.84 / <=1.3.2 Upgrade now. Details: https://cystack.net/disclosures #CyStack #LangChain #AI #Vulnerability #InfoSec https://t.co/iGnX4szcRV

    Post summary

    An advisory discloses CVE-2026-44843, an unsafe deserialization flaw in LangChain, with a CVSS score of 8.2 and affected versions, urging users to upgrade immediately.

    10011137
    3.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Sources (GitHub Advisory Database, CVE-2026-44843) (LangChain repository) (Threat intelligence roundup) TL;DR LangChain's langchain-core library (High severity, CVE-2026-44843) contains an unsafe deserialization vulnerability in its load() function that allows…

    Post summary

    The post announces a newly disclosed CVE-2026-44843 affecting LangChain's langchain-core library, describing an unsafe deserialization flaw in its `load()` function.

    1001064
    289 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - LangChain Server-Side Request Forgery (CVE-2026-44843) A vulnerability in langchain allows attackers to trigger Server-Side Request Forgery (SSRF) through crafted input that causes the application to make unintended outbound requests. Successful exploitation may enable access to internal services, cloud metadata endpoints, or sensitive network resources, potentially leading to credential exposure or further lateral movement. 👉Affected: langchain < 0.3.27 | Upgrade to langchain 0.3.27

    Post summary

    High‑severity SSRF vulnerability in LangChain (CVE‑2026‑44843) affecting versions below 0.3.27, with an upgrade to 0.3.27 recommended.

    00020199
    255 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    The Audit Lag: Why Your Agentic Framework Security Posture Is 90 Days Behind Over the past six weeks, Lyrie's research has documented 17 critical vulnerabilities in agentic frameworks CVE-2026-42208, CVE-2026-44843, CVE-2026-25592, CVE-2026-26030, etc..

    Post summary

    The post enumerates 17 critical CVEs in agentic frameworks but provides no further detail on exploitation, patches, or technical characteristics.

    1000039
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR LangChain's langchain-core library (High severity, CVE-2026-44843) contains an unsafe deserialization vulnerability in its load() function that allows attackers to instantiate arbitrary Python objects with attacker-controlled arguments. Any application using…

    Post summary

    The passage announces CVE-2026-44843 in langchain-core, detailing an unsafe deserialization flaw that can instantiate arbitrary Python objects, with no PoC, exploit code, or mitigation cited.

    1000047
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 10, 2026, GitHub's advisory database published CVE-2026-44843, affecting langchain-core, a foundational library used across thousands of production AI applications that build agentic workflows. The vulnerability exists in the framework's…

    Post summary

    This advisory announces CVE-2026-44843 in langchain-core, detailing its discovery without providing a PoC, exploit code, or patch information.

    1000039
    289 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    10, 2026, — Unsafe Deserialization in LangChain Exposes AI Supply Chain to Arbitrary Code Execution. TL;DR LangChain's langchain-core library (High severity, CVE-2026-44843) contains an unsafe deserialization vulnerability in its load() function that allows attackers to…

    Post summary

    The announcement discloses CVE-2026-44843 as a high‑severity unsafe deserialization flaw in LangChain’s langchain-core library, allowing attackers potentially to execute arbitrary code.

    1000036
    289 followersView on X
  • Dewank Pant@secyourity
    Disclosure

    @Shruti__Lohani and I recently disclosed CVE-2026-44843 in LangChain. Unauthenticated, Zero-Click Remote Credential Theft leading to Persistent Supply-Chain Compromise. Full attack chain writeup below: https://medium.com/@dewankpant/cve-2026-44843-one-chat-message-steals-your-credentials-then-it-gets-worse-264146623aec

    Post summary

    The author has publicly disclosed a newly identified CVE (CVE‑2026‑44843) in LangChain, outlining that it enables unauthenticated, zero‑click remote credential theft leading to supply‑chain compromise, and has provided a Medium write‑up detailing the full attack chain.

    0000031
    57 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    General

    CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! http://dlvr.it/TSTLpV #appsec

    Post summary

    The tweet references CVE-2026-44843 with a dramatic headline but lacks any substantive technical or actionable information.

    0000046
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangchainlangchain---

Explore more