CVE-2026-44843: LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other ...

Added to the CISA Known Exploited Vulnerabilities catalog on 26 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 8.2.

LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other application-controlled payloads using overly broad object allowlists. These paths may call load() wi...

Required action: Review and patch if applicable to your AI infrastructure.