All I Want for Christmas Is Your Secrets: LangGrinch hits LangChain Core (CVE-2025-68664) - Cyata
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A critical deserialization vulnerability (CVE-2025-68664) was discovered in LangChain Core's dumps()/dumpd() functions, where untrusted dictionaries containing the reserved 'lc' key could be serialized and later deserialized as LangChain objects. This enables attackers to extract secrets from environment variables (previously
Table of contents
The short version of the bugMy research story: how I stumbled into itTechnical deep diveWho is affected? The practical checklistDefensive guidance: how to respond in productionThe LangChainJS parallelWhy this matters beyond LangChainWhat this teaches us about AI governanceHow Cyata helps: visibility, risk assessment, control, governanceDisclosure TimelineSort: