logo

LangChainGo Vulnerability Allows Malicious Prompt Injection to Access Sensitive Data

ID: 4dd7cdfe-fea9-5d92-9c06-48b6b1d538dd

STIX ID: report--4dd7cdfe-fea9-5d92-9c06-48b6b1d538dd

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2025-09-15

Date Updated: 2026-04-22

Author: Divya

...
...

**CVE-2025-9556 — LangChainGo arbitrary file read via Gonja template engine:** A server-side template injection vulnerability in LangChainGo's use of the Gonja (Jinja2-compatible) template engine allows an attacker who can supply prompt templates to read arbitrary files on the host (potentially exposing configuration files, private keys, and credentials). The LangChainGo maintainer released an update introducing RenderTemplateFS to isolate template rendering from filesystem access; users should upgrade to the latest release (go get github.com/tmc/langchaingo@latest) and review template usage to ensure RenderTemplateFS is used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.