A critical deserialization vulnerability (CVE-2025-68664) was discovered in LangChain Core's dumps()/dumpd() functions, where untrusted dictionaries containing the reserved 'lc' key could be serialized and later deserialized as LangChain objects. This enables attackers to extract secrets from environment variables (previously

13m read timeFrom cyata.ai
Post cover image
Table of contents
The short version of the bugMy research story: how I stumbled into itTechnical deep diveWho is affected? The practical checklistDefensive guidance: how to respond in productionThe LangChainJS parallelWhy this matters beyond LangChainWhat this teaches us about AI governanceHow Cyata helps: visibility, risk assessment, control, governanceDisclosure Timeline

Sort: