THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-34070 (HIGH 7.5) — LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path inj

[NVD] CVE-2026-34070 (HIGH 7.5) — LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path inj

lownvdPublished 2026-03-31

CVE-2026-34070 CVSS: 7.5 HIGH Published: 2026-03-31T03:15:58.947

LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without validating against directory traversal or absolute path injection. When an application passes user-influenced pro

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34070