THREAT OPS › Threat News › [NVD] CVE-2026-34070 (HIGH 7.5) — LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path inj
[NVD] CVE-2026-34070 (HIGH 7.5) — LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path inj
CVE-2026-34070 CVSS: 7.5 HIGH Published: 2026-03-31T03:15:58.947
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced pro
Indicators of compromise
- CVE-2026-34070cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34070