CVE-2026-34070: LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserializ...

Added to the CISA Known Exploited Vulnerabilities catalog on 31 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an a...

Required action: Review and patch if applicable to your AI infrastructure.