CVE-2025-68664: Critical LangChain Flaw Enables Secret Extraction
ID: 0962609f-4f75-56d1-ace0-acf91b55b829
STIX ID: report--0962609f-4f75-56d1-ace0-acf91b55b829
Feed Name: SOCRadar Blog
CVE-2025-68664 is a high-severity serialization injection vulnerability in LangChain Core (Python) that arises from improper handling of the internal "lc" marker during dumps()/dumpd() and can enable secret extraction and attacker-controlled object instantiation during deserialization; related JS/TS packages are affected by CVE-2025-68665. The advisory lists affected versions, describes mitigations implemented (deserialization allowlist, disabling env secret loading by default, blocking Jinja2 execution), and provides developer guidance to upgrade, audit serialization/deserialization paths, and tighten deserialization policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
