{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-08-14T07:25:26.619Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-08-14T07:23:57.131Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":32,"completeTreeCount":31,"incompleteTreeCount":1,"lockfileRepositoryCount":18,"sbomRepositoryCount":4,"artifactRepositoryCount":21,"resolvedRepositoryCount":31,"resolvedArtifactRepositoryCount":21,"dependencyFileCount":32,"parsedFileCount":31,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":3650,"metadataResolvedCount":3640,"metadataNotFoundCount":10,"osvEvaluatedVersionCount":3650,"codeRadarRepositoryCount":32},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":8000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":32,"packageCount":2274,"aiPackageCount":44,"resolvedComponentCount":6003,"resolvedVersionCount":3650,"providerExposureRepositoryCount":7,"licenseExpressionCount":53,"knownLicensePackageCount":2244,"unknownLicensePackageCount":30,"advisoryCount":643,"matchedAdvisoryRepositoryCount":29,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":20,"repositoryShare":0.625}},"kind":"repository","entity":{"id":"opencode:12475","slug":"opencode-12475","gitlabProjectId":12475,"name":"ai-sr-litscreen","pathWithNamespace":"OpenBfS/kemf/ai-sr-litscreen","description":"Programmable large‑language‑model workflows for high‑sensitivity, cost‑efficient title and abstract screening in systematic reviews, including ready‑to‑run Jupyter notebooks for open‑source and OpenAI ‘mini’ models and example input templates.","webUrl":"https://gitlab.opencode.de/OpenBfS/kemf/ai-sr-litscreen","commitSha":"1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","commitUrl":"https://gitlab.opencode.de/OpenBfS/kemf/ai-sr-litscreen/-/commit/1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","lastActivityAt":"2026-08-13T12:13:52.094Z","headCommittedAt":"2026-08-10T17:43:00.000Z","tree":{"complete":true,"entryCount":14,"truncated":false},"files":[],"resolvedComponentCount":9,"artifactResolvedComponentCount":0,"exactManifestPinCount":9,"packageCount":9,"ecosystems":["pypi"],"aiPackageCount":9,"licenseExpressionCount":4,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-2g6r-c272-w58r","GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-5chr-fjjv-38qv","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-c67j-w6g6-q2cm","GHSA-fv5p-p927-qmxr","GHSA-gr75-jv2w-4656","GHSA-jw8x-6495-233v","GHSA-m42m-m8cr-8m58","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-q25c-c977-4cmh","GHSA-qh6h-p6c9-ff54","GHSA-r7w7-9xr2-qq2r","PYSEC-2024-115","PYSEC-2024-323"],"advisoryCount":18,"providers":[{"id":"openai","label":"OpenAI"},{"id":"ollama","label":"Ollama"}]},"evidence":{"files":[{"path":"requirements.txt","kind":"exact-manifest-pin","sourceUrl":"https://gitlab.opencode.de/OpenBfS/kemf/ai-sr-litscreen/-/blob/1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428/requirements.txt","commitSha":"1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","blobSha":"de2aedada3ed28288167bfa22e0b922d0a82b90f","state":"parsed","componentCount":9}],"occurrenceCount":9},"related":{"packages":[{"id":"package:pypi:langchain-core","slug":"langchain-core-82117efb","identity":"pypi:langchain-core","label":"LangChain Core","aiRelevant":true,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["0.3.45"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-community","slug":"langchain-community-b296254c","identity":"pypi:langchain-community","label":"LangChain Community","aiRelevant":true,"provider":null,"advisoryCount":4,"licenseExpressions":["MIT"],"versions":["0.3.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain","slug":"langchain-2b3b6a0b","identity":"pypi:langchain","label":"LangChain","aiRelevant":true,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["0.3.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-text-splitters","slug":"langchain-text-splitters-0c057788","identity":"pypi:langchain-text-splitters","label":"LangChain · Text Splitters","aiRelevant":true,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["0.3.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-openai","slug":"langchain-openai-4985188e","identity":"pypi:langchain-openai","label":"LangChain OpenAI","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":1,"licenseExpressions":["MIT"],"versions":["0.3.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:scikit-learn","slug":"scikit-learn-ab0941d9","identity":"pypi:scikit-learn","label":"scikit-learn","aiRelevant":true,"provider":null,"advisoryCount":1,"licenseExpressions":["BSD-3-Clause","non-standard"],"versions":["1.3.2"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:ollama","slug":"ollama-0b25d881","identity":"pypi:ollama","label":"Ollama SDK","aiRelevant":true,"provider":{"id":"ollama","label":"Ollama"},"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.3.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:openai","slug":"openai-0dd26ac5","identity":"pypi:openai","label":"OpenAI SDK","aiRelevant":true,"provider":{"id":"openai","label":"OpenAI"},"advisoryCount":0,"licenseExpressions":["Apache-2.0"],"versions":["1.78.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-ollama","slug":"langchain-ollama-c606221f","identity":"pypi:langchain-ollama","label":"LangChain · Ollama","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.2.0"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]}],"vulnerabilities":[{"id":"GHSA-2g6r-c272-w58r","slug":"ghsa-2g6r-c272-w58r-4bbbcb01","dossier":false,"summary":"LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","aliases":["CVE-2026-26013","PYSEC-2026-2562"],"sourceIds":["GHSA-2g6r-c272-w58r","PYSEC-2026-2562"],"published":"2026-02-11T14:23:13Z","modified":"2026-07-13T16:43:30.756724986Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-2g6r-c272-w58r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26013"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/2b4b1dc29a833d4053deba4c2b77a3848c834565"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.11"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g6r-c272-w58r"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-3644-q5cj-c5c7","slug":"ghsa-3644-q5cj-c5c7-4c578cf2","dossier":false,"summary":"LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","aliases":["CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"sourceIds":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"published":"2026-05-13T15:29:30Z","modified":"2026-07-13T16:43:39.736848907Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3644-q5cj-c5c7"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-classic"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"}],"versionKeys":["pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4"],"packageCount":3,"repositoryCount":4},{"id":"GHSA-45pg-36p6-83v9","slug":"ghsa-45pg-36p6-83v9-9505da12","dossier":false,"summary":"Langchain SQL Injection vulnerability","aliases":["CVE-2024-8309","PYSEC-2024-115","PYSEC-2026-1507"],"sourceIds":["GHSA-45pg-36p6-83v9"],"published":"2024-10-29T15:32:05Z","modified":"2026-07-07T17:57:12.591755527Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8309"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972e"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5chr-fjjv-38qv","slug":"ghsa-5chr-fjjv-38qv-5f3dd755","dossier":false,"summary":"langchain-core allows unauthorized users to read arbitrary files from the host file system","aliases":["CVE-2024-10940","PYSEC-2026-1517"],"sourceIds":["GHSA-5chr-fjjv-38qv","PYSEC-2026-1517"],"published":"2025-03-20T12:32:41Z","modified":"2026-07-07T17:56:35.905913395Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10940"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/7d481f10102f43559cc57bcad7eba291067939ee"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/e711034713259ae448981bc0fd1d7a5671499c31"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5chr-fjjv-38qv"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-6qv9-48xg-fc7f","slug":"ghsa-6qv9-48xg-fc7f-6f0bc426","dossier":false,"summary":"LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","aliases":["CVE-2025-65106","PYSEC-2026-1518"],"sourceIds":["GHSA-6qv9-48xg-fc7f","PYSEC-2026-1518"],"published":"2025-11-20T17:42:12Z","modified":"2026-07-07T17:57:16.939269197Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-6qv9-48xg-fc7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65106"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c4b6ba254e1a49ed91f2e268e6484011c540542a"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/fa7789d6c21222b85211755d822ef698d3b34e00"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6qv9-48xg-fc7f"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-926x-3r5x-gfhw","slug":"ghsa-926x-3r5x-gfhw-b7d12e65","dossier":false,"summary":"LangChain has incomplete f-string validation in prompt templates","aliases":["CVE-2026-40087","PYSEC-2026-2563"],"sourceIds":["GHSA-926x-3r5x-gfhw","PYSEC-2026-2563"],"published":"2026-04-08T21:51:32Z","modified":"2026-07-13T16:42:42.901211235Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-926x-3r5x-gfhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40087"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36612"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36613"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/6bab0ba3c12328008ddca3e0d54ff5a6151cd27b"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/af2ed47c6f008cdd551f3c0d87db3774c8dfe258"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.84"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.28"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-926x-3r5x-gfhw"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-c67j-w6g6-q2cm","slug":"ghsa-c67j-w6g6-q2cm-a4c5c0cf","dossier":false,"summary":"LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","aliases":["CVE-2025-68664","PYSEC-2026-373"],"sourceIds":["GHSA-c67j-w6g6-q2cm","PYSEC-2026-373"],"published":"2025-12-23T18:46:13Z","modified":"2026-07-02T13:00:05.018724776Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68664"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34455"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34458"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/d9ec4c5cc78960abd37da79b0250f5642e6f0ce6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.81"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c67j-w6g6-q2cm"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-fv5p-p927-qmxr","slug":"ghsa-fv5p-p927-qmxr-2692dd04","dossier":false,"summary":"LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass","aliases":["CVE-2026-41481","PYSEC-2026-77"],"sourceIds":["GHSA-fv5p-p927-qmxr","PYSEC-2026-77"],"published":"2026-04-16T22:53:32Z","modified":"2026-06-06T01:15:07.890699366Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-fv5p-p927-qmxr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41481"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-text-splitters/PYSEC-2026-77.yaml"}],"versionKeys":["pypi:langchain-text-splitters@0.3.2","pypi:langchain-text-splitters@1.1.0"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-gr75-jv2w-4656","slug":"ghsa-gr75-jv2w-4656-a5b8c61e","dossier":false,"summary":"LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","aliases":["CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556"],"sourceIds":["GHSA-gr75-jv2w-4656","PYSEC-2026-2192"],"published":"2026-06-16T15:03:14Z","modified":"2026-08-07T08:11:57.170704540Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55443"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"}],"versionKeys":["pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langchain@1.2.6"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-jw8x-6495-233v","slug":"ghsa-jw8x-6495-233v-cb32b711","dossier":false,"summary":"scikit-learn sensitive data leakage vulnerability","aliases":["CVE-2024-5206","PYSEC-2024-110"],"sourceIds":["GHSA-jw8x-6495-233v","PYSEC-2024-110"],"published":"2024-06-06T19:16:00Z","modified":"2026-06-10T17:02:43.910139851Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5206"},{"type":"FIX","url":"https://github.com/scikit-learn/scikit-learn/commit/70ca21f106b603b611da73012c9ade7cd8e438b8"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/scikit-learn/PYSEC-2024-110.yaml"},{"type":"PACKAGE","url":"https://github.com/scikit-learn/scikit-learn"},{"type":"WEB","url":"https://huntr.com/bounties/14bc0917-a85b-4106-a170-d09d5191517c"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jw8x-6495-233v"}],"versionKeys":["pypi:scikit-learn@1.3.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-m42m-m8cr-8m58","slug":"ghsa-m42m-m8cr-8m58-f064d587","dossier":false,"summary":"LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing","aliases":["CVE-2025-6985","PYSEC-2026-1520"],"sourceIds":["GHSA-m42m-m8cr-8m58","PYSEC-2026-1520"],"published":"2025-10-06T18:31:07Z","modified":"2026-07-07T17:56:17.555935519Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6985"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/31819"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/43eef435505a1c907227b724c0c760ad5fc01790"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/cf78abbb-df3b-43de-b6ee-132b73ff8331"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-text-splitters"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-m42m-m8cr-8m58"}],"versionKeys":["pypi:langchain-text-splitters@0.3.2"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-pc6w-59fv-rh23","slug":"ghsa-pc6w-59fv-rh23-cab9cb2f","dossier":false,"summary":"Langchain Community Vulnerable to XML External Entity (XXE) Attacks","aliases":["CVE-2025-6984","PYSEC-2026-1515"],"sourceIds":["GHSA-pc6w-59fv-rh23","PYSEC-2026-1515"],"published":"2025-09-04T12:30:42Z","modified":"2026-07-07T17:56:45.822570559Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6984"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain-community"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23"},{"type":"WEB","url":"https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pc6w-59fv-rh23"}],"versionKeys":["pypi:langchain-community@0.2.7","pypi:langchain-community@0.3.5","pypi:langchain-community@0.3.7"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-pjwx-r37v-7724","slug":"ghsa-pjwx-r37v-7724-2297a72a","dossier":false,"summary":"LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists","aliases":["CVE-2026-44843","PYSEC-2026-2564"],"sourceIds":["GHSA-pjwx-r37v-7724","PYSEC-2026-2564"],"published":"2026-05-08T23:07:32Z","modified":"2026-07-13T16:42:39.210995356Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-pjwx-r37v-7724"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44843"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwx-r37v-7724"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-q25c-c977-4cmh","slug":"ghsa-q25c-c977-4cmh-8e74e348","dossier":false,"summary":"Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever","aliases":["CVE-2024-3095","PYSEC-2026-1516"],"sourceIds":["GHSA-q25c-c977-4cmh","PYSEC-2026-1516"],"published":"2024-06-06T21:30:36Z","modified":"2026-07-07T17:57:27.127785500Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3095"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/24451"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9"},{"type":"WEB","url":"https://huntr.com/bounties/e62d4895-2901-405b-9559-38276b6a5273"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q25c-c977-4cmh"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qh6h-p6c9-ff54","slug":"ghsa-qh6h-p6c9-ff54-caf42ff5","dossier":false,"summary":"LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions","aliases":["CVE-2026-34070","PYSEC-2026-2193"],"sourceIds":["GHSA-qh6h-p6c9-ff54","PYSEC-2026-2193"],"published":"2026-03-27T19:45:00Z","modified":"2026-07-13T07:26:33.913236655Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-qh6h-p6c9-ff54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34070"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/27add913474e01e33bededf4096151130ba0d47c"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core==1.2.22"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34070"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34070.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24766"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453287"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-r7w7-9xr2-qq2r","slug":"ghsa-r7w7-9xr2-qq2r-7a3a0a91","dossier":false,"summary":"langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding","aliases":["CVE-2026-41488","PYSEC-2026-76"],"sourceIds":["GHSA-r7w7-9xr2-qq2r","PYSEC-2026-76"],"published":"2026-04-16T23:00:12Z","modified":"2026-06-06T01:15:07.912179267Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-r7w7-9xr2-qq2r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41488"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain-openai/PYSEC-2026-76.yaml"}],"versionKeys":["pypi:langchain-openai@0.2.8","pypi:langchain-openai@0.3.0","pypi:langchain-openai@1.1.7","pypi:langchain-openai@1.1.9"],"packageCount":1,"repositoryCount":4},{"id":"PYSEC-2024-323","slug":"pysec-2024-323-1dd96856","dossier":false,"summary":null,"aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514"],"sourceIds":["PYSEC-2024-323"],"published":"2024-09-17T12:15:02.977Z","modified":"2026-07-13T07:26:23.643495355Z","checkedAt":"2026-08-14T07:25:26.619Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"}],"versionKeys":["pypi:langchain@0.2.7"],"packageCount":1,"repositoryCount":1}]}}
