{"schemaVersion":"ki-abhaengigkeitsatlas/v1","dataset":"german-public-sector-ai-dependency-atlas","parserVersion":"1","generatedAt":"2026-07-20T14:37:29.537Z","trackingSince":"2026-07-18T21:20:30.334Z","source":{"codeRadar":{"dataset":"german-public-sector-ai-code-radar","generatedAt":"2026-07-20T14:36:19.763Z","parserVersion":"3","url":"https://i6eal.de/tools/ki-code-radar/"},"openCode":{"label":"openCode GitLab","url":"https://gitlab.opencode.de/"},"depsDev":{"label":"deps.dev API v3","url":"https://docs.deps.dev/api/v3/"},"osv":{"label":"OSV API","url":"https://google.github.io/osv.dev/api/"},"spdx":{"label":"SPDX License List","url":"https://spdx.org/licenses/","version":"3.28.0","releaseDate":"2026-02-20T00:00:00Z"}},"coverage":{"repositoryCount":30,"completeTreeCount":29,"incompleteTreeCount":1,"lockfileRepositoryCount":17,"sbomRepositoryCount":4,"artifactRepositoryCount":20,"resolvedRepositoryCount":29,"resolvedArtifactRepositoryCount":20,"dependencyFileCount":33,"parsedFileCount":32,"parseErrorCount":1,"unsupportedFileCount":0,"evaluatedVersionCount":4205,"metadataResolvedCount":4191,"metadataNotFoundCount":14,"osvEvaluatedVersionCount":4205,"codeRadarRepositoryCount":30},"methodology":{"componentParserSchemaVersion":"ki-dependency-atlas-components/v1","candidateBoundary":"repositories_with_exact_ai_code_evidence","resolvedVersionBoundary":"exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin","manifestRangesResolved":false,"latestVersionSubstitution":false,"containerTagsVulnerabilityChecked":false,"osvClaim":"osv_matched_observed_resolved_package_version_at_collection_time","depsDevLicenseSemantics":"spdx_expressions_as_reported_without_inferred_compatibility","providerSemantics":"package_interface_presence_not_api_configuration_procurement_or_use","generativeAiUsed":false,"scoreUsed":false,"treeEntryCeiling":2500,"fileByteCeiling":5242880,"uniqueVersionCeiling":5000,"observedFormats":["package-lock.json / npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins"]},"summary":{"repositoryCount":30,"packageCount":2831,"aiPackageCount":41,"resolvedComponentCount":7181,"resolvedVersionCount":4205,"providerExposureRepositoryCount":7,"licenseExpressionCount":57,"knownLicensePackageCount":2796,"unknownLicensePackageCount":35,"advisoryCount":572,"matchedAdvisoryRepositoryCount":25,"topPackage":{"id":"package:pypi:openai","slug":"openai-0dd26ac5","label":"OpenAI SDK","repositoryCount":18,"repositoryShare":0.6}},"kind":"repository","entity":{"id":"opencode:4166","slug":"opencode-4166","gitlabProjectId":4166,"name":"ai-legal-graph","pathWithNamespace":"iorb/ai-legal-graph","description":null,"webUrl":"https://gitlab.opencode.de/iorb/ai-legal-graph","commitSha":"8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be","commitUrl":"https://gitlab.opencode.de/iorb/ai-legal-graph/-/commit/8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be","lastActivityAt":"2025-04-10T15:29:54.353Z","headCommittedAt":"2025-03-31T12:14:45.000Z","tree":{"complete":true,"entryCount":234,"truncated":false},"files":[],"resolvedComponentCount":8,"artifactResolvedComponentCount":0,"exactManifestPinCount":8,"packageCount":8,"ecosystems":["pypi"],"aiPackageCount":8,"licenseExpressionCount":1,"unknownLicensePackageCount":0,"advisoryIds":["GHSA-2g6r-c272-w58r","GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-5chr-fjjv-38qv","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-c67j-w6g6-q2cm","GHSA-g48c-2wqr-h844","GHSA-gr75-jv2w-4656","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-q25c-c977-4cmh","GHSA-qh6h-p6c9-ff54","GHSA-w39p-vh2g-g8g5","PYSEC-2024-115","PYSEC-2024-323"],"advisoryCount":16,"providers":[]},"evidence":{"files":[{"path":"requirements.txt","kind":"exact-manifest-pin","sourceUrl":"https://gitlab.opencode.de/iorb/ai-legal-graph/-/blob/8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be/requirements.txt","commitSha":"8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be","blobSha":"eb8e9a474c655bc81e1a5841cf757dec75775529","state":"parsed","componentCount":8}],"occurrenceCount":8},"related":{"packages":[{"id":"package:pypi:langchain-core","slug":"langchain-core-82117efb","identity":"pypi:langchain-core","label":"LangChain Core","aiRelevant":true,"provider":null,"advisoryCount":7,"licenseExpressions":["MIT"],"versions":["0.2.28"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-community","slug":"langchain-community-b296254c","identity":"pypi:langchain-community","label":"LangChain Community","aiRelevant":true,"provider":null,"advisoryCount":4,"licenseExpressions":["MIT"],"versions":["0.2.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain","slug":"langchain-2b3b6a0b","identity":"pypi:langchain","label":"LangChain","aiRelevant":true,"provider":null,"advisoryCount":3,"licenseExpressions":["MIT"],"versions":["0.2.7"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langgraph","slug":"langgraph-6c1c645e","identity":"pypi:langgraph","label":"LangGraph","aiRelevant":true,"provider":null,"advisoryCount":2,"licenseExpressions":["MIT"],"versions":["0.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-experimental","slug":"langchain-experimental-7a9ed002","identity":"pypi:langchain-experimental","label":"LangChain · Experimental","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.63"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-groq","slug":"langchain-groq-aed894e4","identity":"pypi:langchain-groq","label":"LangChain · Groq","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.5"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-huggingface","slug":"langchain-huggingface-89b06dab","identity":"pypi:langchain-huggingface","label":"LangChain · Hugging Face","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.0.3"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]},{"id":"package:pypi:langchain-ollama","slug":"langchain-ollama-c606221f","identity":"pypi:langchain-ollama","label":"LangChain · Ollama","aiRelevant":true,"provider":null,"advisoryCount":0,"licenseExpressions":["MIT"],"versions":["0.1.1"],"dossier":true,"occurrenceCount":1,"directOccurrenceCount":1,"evidenceFiles":["requirements.txt"]}],"vulnerabilities":[{"id":"GHSA-2g6r-c272-w58r","slug":"ghsa-2g6r-c272-w58r-4bbbcb01","dossier":false,"summary":"LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages","aliases":["CVE-2026-26013","PYSEC-2026-2562"],"sourceIds":["GHSA-2g6r-c272-w58r","PYSEC-2026-2562"],"published":"2026-02-11T14:23:13Z","modified":"2026-07-13T16:43:30.756724986Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-2g6r-c272-w58r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26013"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/2b4b1dc29a833d4053deba4c2b77a3848c834565"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.11"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2g6r-c272-w58r"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-3644-q5cj-c5c7","slug":"ghsa-3644-q5cj-c5c7-4c578cf2","dossier":false,"summary":"LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning","aliases":["CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"sourceIds":["GHSA-3644-q5cj-c5c7","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582"],"published":"2026-05-13T15:29:30Z","modified":"2026-07-13T16:43:39.736848907Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langsmith-sdk/security/advisories/GHSA-3644-q5cj-c5c7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45134"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langsmith-sdk"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3644-q5cj-c5c7"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-classic"},{"type":"PACKAGE","url":"https://pypi.org/project/langsmith"}],"versionKeys":["pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4"],"packageCount":3,"repositoryCount":3},{"id":"GHSA-45pg-36p6-83v9","slug":"ghsa-45pg-36p6-83v9-9505da12","dossier":false,"summary":"Langchain SQL Injection vulnerability","aliases":["CVE-2024-8309","PYSEC-2024-115","PYSEC-2026-1507"],"sourceIds":["GHSA-45pg-36p6-83v9"],"published":"2024-10-29T15:32:05Z","modified":"2026-07-07T17:57:12.591755527Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8309"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/64c317eba05fbac0c6a6fc5aa192bc0d7130972e"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c2a3021bb0c5f54649d380b42a0684ca5778c255"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-115.yaml"},{"type":"WEB","url":"https://huntr.com/bounties/8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-5chr-fjjv-38qv","slug":"ghsa-5chr-fjjv-38qv-5f3dd755","dossier":false,"summary":"langchain-core allows unauthorized users to read arbitrary files from the host file system","aliases":["CVE-2024-10940","PYSEC-2026-1517"],"sourceIds":["GHSA-5chr-fjjv-38qv","PYSEC-2026-1517"],"published":"2025-03-20T12:32:41Z","modified":"2026-07-07T17:56:35.905913395Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-10940"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/7d481f10102f43559cc57bcad7eba291067939ee"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/e711034713259ae448981bc0fd1d7a5671499c31"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5chr-fjjv-38qv"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-6qv9-48xg-fc7f","slug":"ghsa-6qv9-48xg-fc7f-6f0bc426","dossier":false,"summary":"LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates","aliases":["CVE-2025-65106","PYSEC-2026-1518"],"sourceIds":["GHSA-6qv9-48xg-fc7f","PYSEC-2026-1518"],"published":"2025-11-20T17:42:12Z","modified":"2026-07-07T17:57:16.939269197Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-6qv9-48xg-fc7f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65106"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/c4b6ba254e1a49ed91f2e268e6484011c540542a"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/fa7789d6c21222b85211755d822ef698d3b34e00"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-6qv9-48xg-fc7f"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-926x-3r5x-gfhw","slug":"ghsa-926x-3r5x-gfhw-b7d12e65","dossier":false,"summary":"LangChain has incomplete f-string validation in prompt templates","aliases":["CVE-2026-40087","PYSEC-2026-2563"],"sourceIds":["GHSA-926x-3r5x-gfhw","PYSEC-2026-2563"],"published":"2026-04-08T21:51:32Z","modified":"2026-07-13T16:42:42.901211235Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-926x-3r5x-gfhw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40087"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36612"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/36613"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/6bab0ba3c12328008ddca3e0d54ff5a6151cd27b"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/af2ed47c6f008cdd551f3c0d87db3774c8dfe258"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.84"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.28"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-926x-3r5x-gfhw"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-c67j-w6g6-q2cm","slug":"ghsa-c67j-w6g6-q2cm-a4c5c0cf","dossier":false,"summary":"LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs","aliases":["CVE-2025-68664","PYSEC-2026-373"],"sourceIds":["GHSA-c67j-w6g6-q2cm","PYSEC-2026-373"],"published":"2025-12-23T18:46:13Z","modified":"2026-07-02T13:00:05.018724776Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-c67j-w6g6-q2cm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-68664"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34455"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/34458"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/d9ec4c5cc78960abd37da79b0250f5642e6f0ce6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D0.3.81"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core%3D%3D1.2.5"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-c67j-w6g6-q2cm"}],"versionKeys":["pypi:langchain-core@0.2.28"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-g48c-2wqr-h844","slug":"ghsa-g48c-2wqr-h844-48f35247","dossier":false,"summary":"LangGraph checkpoint loading has unsafe msgpack deserialization","aliases":["CVE-2026-28277","PYSEC-2026-83"],"sourceIds":["GHSA-g48c-2wqr-h844","PYSEC-2026-83"],"published":"2026-03-05T20:16:15.677Z","modified":"2026-06-06T01:00:08.116125988Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-g48c-2wqr-h844"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28277"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/langgraph/PYSEC-2026-83.yaml"}],"versionKeys":["pypi:langgraph@0.1.1","pypi:langgraph@0.3.21","pypi:langgraph@1.0.6"],"packageCount":1,"repositoryCount":3},{"id":"GHSA-gr75-jv2w-4656","slug":"ghsa-gr75-jv2w-4656-a5b8c61e","dossier":false,"summary":"LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders","aliases":["CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556"],"sourceIds":["GHSA-gr75-jv2w-4656","PYSEC-2026-2192"],"published":"2026-06-16T15:03:14Z","modified":"2026-07-13T16:43:09.845932020Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55443"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"}],"versionKeys":["pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langchain@1.2.6","pypi:langchain@1.3.8"],"packageCount":1,"repositoryCount":4},{"id":"GHSA-pc6w-59fv-rh23","slug":"ghsa-pc6w-59fv-rh23-cab9cb2f","dossier":false,"summary":"Langchain Community Vulnerable to XML External Entity (XXE) Attacks","aliases":["CVE-2025-6984","PYSEC-2026-1515"],"sourceIds":["GHSA-pc6w-59fv-rh23","PYSEC-2026-1515"],"published":"2025-09-04T12:30:42Z","modified":"2026-07-07T17:56:45.822570559Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-6984"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain-community/commit/e842452108089524e22c3a2ced851c021884556f"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain-community"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/blob/d79b5813a0b3b243c612b77013768995e46c4337/libs/langchain/langchain/document_loaders/evernote.py#L1-L23"},{"type":"WEB","url":"https://huntr.com/bounties/a6b521cf-258c-41c0-9edb-d8ef976abb2a"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pc6w-59fv-rh23"}],"versionKeys":["pypi:langchain-community@0.2.7","pypi:langchain-community@0.3.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-pjwx-r37v-7724","slug":"ghsa-pjwx-r37v-7724-2297a72a","dossier":false,"summary":"LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists","aliases":["CVE-2026-44843","PYSEC-2026-2564"],"sourceIds":["GHSA-pjwx-r37v-7724","PYSEC-2026-2564"],"published":"2026-05-08T23:07:32Z","modified":"2026-07-13T16:42:39.210995356Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-pjwx-r37v-7724"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44843"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pjwx-r37v-7724"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-q25c-c977-4cmh","slug":"ghsa-q25c-c977-4cmh-8e74e348","dossier":false,"summary":"Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever","aliases":["CVE-2024-3095","PYSEC-2026-1516"],"sourceIds":["GHSA-q25c-c977-4cmh","PYSEC-2026-1516"],"published":"2024-06-06T21:30:36Z","modified":"2026-07-07T17:57:27.127785500Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3095"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/pull/24451"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"WEB","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-community%3D%3D0.2.9"},{"type":"WEB","url":"https://huntr.com/bounties/e62d4895-2901-405b-9559-38276b6a5273"},{"type":"PACKAGE","url":"https://pypi.org/project/langchain-community"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q25c-c977-4cmh"}],"versionKeys":["pypi:langchain-community@0.2.7"],"packageCount":1,"repositoryCount":1},{"id":"GHSA-qh6h-p6c9-ff54","slug":"ghsa-qh6h-p6c9-ff54-caf42ff5","dossier":false,"summary":"LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions","aliases":["CVE-2026-34070","PYSEC-2026-2193"],"sourceIds":["GHSA-qh6h-p6c9-ff54","PYSEC-2026-2193"],"published":"2026-03-27T19:45:00Z","modified":"2026-07-13T07:26:33.913236655Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}],"references":[{"type":"EVIDENCE","url":"https://github.com/langchain-ai/langchain/security/advisories/GHSA-qh6h-p6c9-ff54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34070"},{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/27add913474e01e33bededf4096151130ba0d47c"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langchain"},{"type":"ADVISORY","url":"https://github.com/langchain-ai/langchain/releases/tag/langchain-core==1.2.22"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-34070"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34070.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24766"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:37275"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453287"}],"versionKeys":["pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7"],"packageCount":1,"repositoryCount":2},{"id":"GHSA-w39p-vh2g-g8g5","slug":"ghsa-w39p-vh2g-g8g5-47880dfe","dossier":false,"summary":"LangGraph SDK has unsafe URL path construction","aliases":["CVE-2026-48776","PYSEC-2026-2194","PYSEC-2026-2575"],"sourceIds":["GHSA-w39p-vh2g-g8g5","PYSEC-2026-2194","PYSEC-2026-2575"],"published":"2026-06-17T10:55:15.113Z","modified":"2026-07-13T16:42:27.619863658Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}],"references":[{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/security/advisories/GHSA-w39p-vh2g-g8g5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48776"},{"type":"PACKAGE","url":"https://github.com/langchain-ai/langgraph"},{"type":"WEB","url":"https://github.com/langchain-ai/langgraph/releases/tag/sdk%3D%3D0.3.15"},{"type":"PACKAGE","url":"https://pypi.org/project/langgraph-sdk"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w39p-vh2g-g8g5"}],"versionKeys":["pypi:langgraph-sdk@0.3.3","pypi:langgraph@0.1.1"],"packageCount":2,"repositoryCount":2},{"id":"PYSEC-2024-323","slug":"pysec-2024-323-1dd96856","dossier":false,"summary":null,"aliases":["CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514"],"sourceIds":["PYSEC-2024-323"],"published":"2024-09-17T12:15:02.977Z","modified":"2026-07-13T07:26:23.643495355Z","checkedAt":"2026-07-20T14:37:29.537Z","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}],"references":[{"type":"FIX","url":"https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"}],"versionKeys":["pypi:langchain@0.2.7"],"packageCount":1,"repositoryCount":1}]}}
