Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical vulnerability in LangChain core exposes secrets via serialization injection
Identity

Critical vulnerability in LangChain core exposes secrets via serialization injection

userBy userDecember 26, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 26, 2025Ravi LakshmananAI Security / DevSecOps

Critical vulnerability in LangChain core

A critical security flaw has been revealed in LangChain Core. It can also be exploited by an attacker to steal sensitive secrets and influence large-scale language model (LLM) responses through prompt injection.

LangChain Core (i.e. langchain-core) is a core Python package that is part of the LangChain ecosystem and provides core interfaces and model-agnostic abstractions for building LLM-powered applications.

This vulnerability is tracked as CVE-2025-68664 and has a CVSS score of 9.3 out of 10.0. Security researcher Yarden Porat reportedly reported the vulnerability on December 4, 2025. The code name is LangGrinch.

“A serialization injection vulnerability exists in LangChain’s dumps() and dumpd() functions,” project administrators said in an advisory. “The function does not escape the dictionary using the ‘lc’ key when serializing a free-form dictionary.”

cyber security

“The ‘lc’ key is used internally by LangChain to mark serialized objects. If user-controlled data contains this key structure, it will be treated as a regular LangChain object during deserialization rather than plain user data.”

According to Cyata researcher Porat, the crux of the issue involves two functions that fail to escape user-controlled dictionaries containing the “lc” key. The “lc” marker represents a LangChain object in the framework’s internal serialization format.

“So if an attacker were able to serialize and then deserialize content containing the ‘lc’ key in the LangChain orchestration loop, an arbitrary insecure object could be instantiated, triggering many paths in the attacker’s favor,” Porat said.

This can have a variety of consequences, including extracting secrets from environment variables when deserialization is performed with “secrets_from_env=True” (previously set by default), instantiating classes within pre-approved trusted namespaces such as langchain_core, langchain, langchain_community, and even potentially leading to arbitrary code execution via Jinja2 templates.

Additionally, the escape bug allows injection of LangChain object structures via user-controlled fields such as metadata via prompt injection, additional _kwargs, or response metadata.

A patch released by LangChain introduces new restrictive defaults for load() and loads() with an allowlist parameter “allowed_objects” that allows users to specify which classes can be serialized/deserialized. Additionally, Jinja2 templates are now blocked by default and the “secrets_from_env” option is set to “False” to disable automatic secret loading from the environment.

The following versions of langchain-core are affected by CVE-2025-68664.

>= 1.0.0, < 1.2.5 (fixed in 1.2.5) < 0.3.81 (fixed in 0.3.81)

It is worth noting that a similar serialization injection flaw exists in LangChain.js. This is also due to not properly escaping the object with the “lc” key, allowing secret extraction and prompt injection. This vulnerability has been assigned CVE identifier CVE-2025-68665 (CVSS score: 8.6).

cyber security

Affects the following npm packages:

@langchain/core >= 1.0.0, < 1.1.8 (fixed in 1.1.8) @langchain/core < 0.3.80 (0.3.80で修正) langchain >= 1.0.0, < 1.2.3 (fixed in 1.2.3) langchain < 0.3.37 (fixed in 0.3.37)

Given the importance of this vulnerability, we recommend that users update to the patched version as soon as possible for optimal protection.

“The most common attack vector is via LLM response fields such as addition_kwargs and response_metadata, which can be controlled by prompt injection and serialized/deserialized in streaming operations,” Porat said. “This is exactly the intersection of ‘AI meets traditional security’ where organizations are caught off guard. The LLM output is an untrusted input.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFlat-headed cat not seen in Thailand for 30 years rediscovered
Next Article These are the cybersecurity stories we’ll be jealous of in 2025
user
  • Website

Related Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

December 30, 2025

How to integrate AI into modern SOC workflows

December 30, 2025

Mustang Panda uses signed kernel-mode rootkit to load TONESHELL backdoor

December 30, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Silver Fox targets Indian users with tax-themed emails delivering ValleyRAT malware

Can we bring American infrastructure into the modern era?

How to integrate AI into modern SOC workflows

The year AI moves from experimentation to execution

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.