CVE-2026-40087: LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some pr...

Added to the CISA Known Exploited Vulnerabilities catalog on 09 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.3.

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.84 and 1.2.28, LangChain's f-string prompt-template validation was incomplete in two respects. First, some prompt template classes accepted f-string templates and formatted them without enforcing the same attr...

Required action: Review and patch if applicable to your AI infrastructure.