Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-r399-636x-v7f6 | LangChain serialization injection vulnerability enables secret extraction |
Tue, 13 Jan 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langchain.js Langchain langchain\/core |
|
| CPEs | cpe:2.3:a:langchain:langchain.js:*:*:*:*:*:*:*:* cpe:2.3:a:langchain:langchain\/core:*:*:*:*:*:node.js:*:* |
|
| Vendors & Products |
Langchain
Langchain langchain.js Langchain langchain\/core |
Thu, 25 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 24 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain-ai
Langchain-ai langchainjs |
|
| Vendors & Products |
Langchain-ai
Langchain-ai langchainjs |
Tue, 23 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists in LangChain JS's toJSON() method (and subsequently when string-ifying objects using JSON.stringify(). The method did not escape objects with 'lc' keys when serializing free-form data in kwargs. The 'lc' key is used internally by LangChain to mark serialized objects. When user-controlled data contains this key structure, it is treated as a legitimate LangChain object during deserialization rather than plain user data. This issue has been patched in @langchain/core versions 0.3.80 and 1.1.8, and langchain versions 0.3.37 and 1.2.3 | |
| Title | LangChain serialization injection vulnerability enables secret extraction | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-24T14:38:40.268Z
Reserved: 2025-12-22T23:28:02.917Z
Link: CVE-2025-68665
Updated: 2025-12-24T14:38:27.420Z
Status : Analyzed
Published: 2025-12-23T23:15:45.097
Modified: 2026-01-13T16:17:22.673
Link: CVE-2025-68665
OpenCVE Enrichment
Updated: 2025-12-24T11:51:43Z
Github GHSA