logo

Case study: Securing AI application supply chains

ID: db6a93b5-3891-550b-8709-899d832aa4bc

STIX ID: report--db6a93b5-3891-550b-8709-899d832aa4bc

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-01-30

Date Updated: 2026-04-28

Author: Microsoft Defender Security Research Team

...
...

Microsoft Defender Security Research describes CVE-2025-68664 (LangGrinch), a critical (CVSS 9.3) serialization injection in the langchain-core Python package where improper handling of a reserved "lc" key during serialization/deserialization can allow attackers to extract environment secrets, instantiate arbitrary classes, and trigger malicious side effects; the advisory provides the root cause analysis, patched versions (0.3.81+ for 0.3.x and 1.2.5+ for 1.x), detection guidance (Defender CSPM, updated scanners, and a KQL hunting query), and remediation recommendations across code, build, and runtime stages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.