logo

CVE-2025-68664: Critical LangChain Flaw Enables Secret Extraction

ID: 0962609f-4f75-56d1-ace0-acf91b55b829

STIX ID: report--0962609f-4f75-56d1-ace0-acf91b55b829

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2025-12-26

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2025-68664 is a high-severity serialization injection vulnerability in LangChain Core (Python) that arises from improper handling of the internal "lc" marker during dumps()/dumpd() and can enable secret extraction and attacker-controlled object instantiation during deserialization; related JS/TS packages are affected by CVE-2025-68665. The advisory lists affected versions, describes mitigations implemented (deserialization allowlist, disabling env secret loading by default, blocking Jinja2 execution), and provides developer guidance to upgrade, audit serialization/deserialization paths, and tighten deserialization policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.