[{"data":1,"prerenderedAt":701},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-12475":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":40,"summary":59,"kind":75,"entity":76,"evidence":121,"related":129},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-08-13T15:26:42.042Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-08-13T15:25:17.361Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.28.0","2026-02-20T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":31,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":30,"parsedFileCount":31,"parseErrorCount":32,"unsupportedFileCount":36,"evaluatedVersionCount":37,"metadataResolvedCount":38,"metadataNotFoundCount":39,"osvEvaluatedVersionCount":37,"codeRadarRepositoryCount":30},32,31,1,18,4,21,0,3650,3640,10,{"componentParserSchemaVersion":41,"candidateBoundary":42,"resolvedVersionBoundary":43,"manifestRangesResolved":44,"latestVersionSubstitution":44,"containerTagsVulnerabilityChecked":44,"osvClaim":45,"depsDevLicenseSemantics":46,"providerSemantics":47,"generativeAiUsed":44,"scoreUsed":44,"treeEntryCeiling":48,"fileByteCeiling":49,"uniqueVersionCeiling":50,"observedFormats":51},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,8000,[52,53,54,55,56,57,58],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":60,"aiPackageCount":61,"resolvedComponentCount":62,"resolvedVersionCount":37,"providerExposureRepositoryCount":63,"licenseExpressionCount":64,"knownLicensePackageCount":65,"unknownLicensePackageCount":66,"advisoryCount":67,"matchedAdvisoryRepositoryCount":68,"topPackage":69},2274,44,6003,7,53,2244,30,642,29,{"id":70,"slug":71,"label":72,"repositoryCount":73,"repositoryShare":74},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",20,0.625,"repository",{"id":77,"slug":78,"gitlabProjectId":79,"name":80,"pathWithNamespace":81,"description":82,"webUrl":83,"commitSha":84,"commitUrl":85,"lastActivityAt":86,"headCommittedAt":87,"tree":88,"files":91,"resolvedComponentCount":92,"artifactResolvedComponentCount":36,"exactManifestPinCount":92,"packageCount":92,"ecosystems":93,"aiPackageCount":92,"licenseExpressionCount":34,"unknownLicensePackageCount":36,"advisoryIds":95,"advisoryCount":33,"providers":114},"opencode:12475","opencode-12475",12475,"ai-sr-litscreen","OpenBfS\u002Fkemf\u002Fai-sr-litscreen","Programmable large‑language‑model workflows for high‑sensitivity, cost‑efficient title and abstract screening in systematic reviews, including ready‑to‑run Jupyter notebooks for open‑source and OpenAI ‘mini’ models and example input templates.","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen","1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen\u002F-\u002Fcommit\u002F1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","2026-08-13T12:13:52.094Z","2026-08-10T17:43:00.000Z",{"complete":89,"entryCount":90,"truncated":44},true,14,[],9,[94],"pypi",[96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113],"GHSA-2g6r-c272-w58r","GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-5chr-fjjv-38qv","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-c67j-w6g6-q2cm","GHSA-fv5p-p927-qmxr","GHSA-gr75-jv2w-4656","GHSA-jw8x-6495-233v","GHSA-m42m-m8cr-8m58","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-q25c-c977-4cmh","GHSA-qh6h-p6c9-ff54","GHSA-r7w7-9xr2-qq2r","PYSEC-2024-115","PYSEC-2024-323",[115,118],{"id":116,"label":117},"openai","OpenAI",{"id":119,"label":120},"ollama","Ollama",{"files":122,"occurrenceCount":92},[123],{"path":124,"kind":125,"sourceUrl":126,"commitSha":84,"blobSha":127,"state":128,"componentCount":92},"requirements.txt","exact-manifest-pin","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen\u002F-\u002Fblob\u002F1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428\u002Frequirements.txt","de2aedada3ed28288167bfa22e0b922d0a82b90f","parsed",{"packages":130,"vulnerabilities":219},[131,142,151,161,171,181,192,202,210],{"id":132,"slug":133,"identity":134,"label":135,"aiRelevant":89,"provider":136,"advisoryCount":63,"licenseExpressions":137,"versions":139,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":141},"package:pypi:langchain-core","langchain-core-82117efb","pypi:langchain-core","LangChain Core",null,[138],"MIT",[140],"0.3.45",[124],{"id":143,"slug":144,"identity":145,"label":146,"aiRelevant":89,"provider":136,"advisoryCount":34,"licenseExpressions":147,"versions":148,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":150},"package:pypi:langchain-community","langchain-community-b296254c","pypi:langchain-community","LangChain Community",[138],[149],"0.3.5",[124],{"id":152,"slug":153,"identity":154,"label":155,"aiRelevant":89,"provider":136,"advisoryCount":156,"licenseExpressions":157,"versions":158,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":160},"package:pypi:langchain","langchain-2b3b6a0b","pypi:langchain","LangChain",3,[138],[159],"0.3.7",[124],{"id":162,"slug":163,"identity":164,"label":165,"aiRelevant":89,"provider":136,"advisoryCount":166,"licenseExpressions":167,"versions":168,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":170},"package:pypi:langchain-text-splitters","langchain-text-splitters-0c057788","pypi:langchain-text-splitters","LangChain · Text Splitters",2,[138],[169],"0.3.2",[124],{"id":172,"slug":173,"identity":174,"label":175,"aiRelevant":89,"provider":176,"advisoryCount":32,"licenseExpressions":177,"versions":178,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":180},"package:pypi:langchain-openai","langchain-openai-4985188e","pypi:langchain-openai","LangChain OpenAI",{"id":116,"label":117},[138],[179],"0.3.0",[124],{"id":182,"slug":183,"identity":184,"label":185,"aiRelevant":89,"provider":136,"advisoryCount":32,"licenseExpressions":186,"versions":189,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":191},"package:pypi:scikit-learn","scikit-learn-ab0941d9","pypi:scikit-learn","scikit-learn",[187,188],"BSD-3-Clause","non-standard",[190],"1.3.2",[124],{"id":193,"slug":194,"identity":195,"label":196,"aiRelevant":89,"provider":197,"advisoryCount":36,"licenseExpressions":198,"versions":199,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":201},"package:pypi:ollama","ollama-0b25d881","pypi:ollama","Ollama SDK",{"id":119,"label":120},[138],[200],"0.3.3",[124],{"id":70,"slug":71,"identity":203,"label":72,"aiRelevant":89,"provider":204,"advisoryCount":36,"licenseExpressions":205,"versions":207,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":209},"pypi:openai",{"id":116,"label":117},[206],"Apache-2.0",[208],"1.78.1",[124],{"id":211,"slug":212,"identity":213,"label":214,"aiRelevant":89,"provider":136,"advisoryCount":36,"licenseExpressions":215,"versions":216,"dossier":89,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":218},"package:pypi:langchain-ollama","langchain-ollama-c606221f","pypi:langchain-ollama","LangChain · Ollama",[138],[217],"0.2.0",[124],[220,255,289,318,346,372,406,440,463,489,518,545,574,596,624,659,684],{"id":96,"slug":221,"dossier":44,"summary":222,"aliases":223,"sourceIds":226,"published":227,"modified":228,"checkedAt":7,"severity":229,"references":233,"versionKeys":251,"packageCount":32,"repositoryCount":156},"ghsa-2g6r-c272-w58r-4bbbcb01","LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages",[224,225],"CVE-2026-26013","PYSEC-2026-2562",[96,225],"2026-02-11T14:23:13Z","2026-07-13T16:43:30.756724986Z",[230],{"type":231,"score":232},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[234,237,240,242,245,247,249],{"type":235,"url":236},"WEB","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",{"type":238,"url":239},"ADVISORY","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-26013",{"type":235,"url":241},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F2b4b1dc29a833d4053deba4c2b77a3848c834565",{"type":243,"url":244},"PACKAGE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain",{"type":235,"url":246},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.11",{"type":243,"url":248},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-core",{"type":238,"url":250},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",[252,253,254],"pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@1.2.7",{"id":97,"slug":256,"dossier":44,"summary":257,"aliases":258,"sourceIds":263,"published":264,"modified":265,"checkedAt":7,"severity":266,"references":269,"versionKeys":284,"packageCount":156,"repositoryCount":34},"ghsa-3644-q5cj-c5c7-4c578cf2","LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning",[259,260,261,262],"CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582",[97,260,261,262],"2026-05-13T15:29:30Z","2026-07-13T16:43:39.736848907Z",[267],{"type":231,"score":268},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[270,272,274,276,278,280,282],{"type":235,"url":271},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk\u002Fsecurity\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":238,"url":273},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45134",{"type":243,"url":275},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk",{"type":243,"url":277},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain",{"type":238,"url":279},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":243,"url":281},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-classic",{"type":243,"url":283},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangsmith",[285,286,287,288],"pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4",{"id":98,"slug":290,"dossier":44,"summary":291,"aliases":292,"sourceIds":295,"published":296,"modified":297,"checkedAt":7,"severity":298,"references":304,"versionKeys":316,"packageCount":32,"repositoryCount":32},"ghsa-45pg-36p6-83v9-9505da12","Langchain SQL Injection vulnerability",[293,112,294],"CVE-2024-8309","PYSEC-2026-1507",[98],"2024-10-29T15:32:05Z","2026-07-07T17:57:12.591755527Z",[299,301],{"type":231,"score":300},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":302,"score":303},"CVSS_V4","CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[305,307,309,311,312,314],{"type":238,"url":306},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-8309",{"type":235,"url":308},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F64c317eba05fbac0c6a6fc5aa192bc0d7130972e",{"type":235,"url":310},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc2a3021bb0c5f54649d380b42a0684ca5778c255",{"type":243,"url":244},{"type":235,"url":313},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain\u002FPYSEC-2024-115.yaml",{"type":235,"url":315},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5",[317],"pypi:langchain-community@0.2.7",{"id":99,"slug":319,"dossier":44,"summary":320,"aliases":321,"sourceIds":324,"published":325,"modified":326,"checkedAt":7,"severity":327,"references":330,"versionKeys":345,"packageCount":32,"repositoryCount":32},"ghsa-5chr-fjjv-38qv-5f3dd755","langchain-core allows unauthorized users to read arbitrary files from the host file system",[322,323],"CVE-2024-10940","PYSEC-2026-1517",[99,323],"2025-03-20T12:32:41Z","2026-07-07T17:56:35.905913395Z",[328],{"type":231,"score":329},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[331,333,335,337,339,340,342,343],{"type":238,"url":332},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-10940",{"type":235,"url":334},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F7d481f10102f43559cc57bcad7eba291067939ee",{"type":235,"url":336},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc1e742347f9701aadba8920e4d1f79a636e50b68",{"type":235,"url":338},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fe711034713259ae448981bc0fd1d7a5671499c31",{"type":243,"url":244},{"type":235,"url":341},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fbe1ee1cb-2147-4ff4-a57b-b6045271cf27",{"type":243,"url":248},{"type":238,"url":344},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5chr-fjjv-38qv",[252],{"id":100,"slug":347,"dossier":44,"summary":348,"aliases":349,"sourceIds":352,"published":353,"modified":354,"checkedAt":7,"severity":355,"references":358,"versionKeys":371,"packageCount":32,"repositoryCount":166},"ghsa-6qv9-48xg-fc7f-6f0bc426","LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates",[350,351],"CVE-2025-65106","PYSEC-2026-1518",[100,351],"2025-11-20T17:42:12Z","2026-07-07T17:57:16.939269197Z",[356],{"type":302,"score":357},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[359,361,363,365,367,368,369],{"type":235,"url":360},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",{"type":238,"url":362},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-65106",{"type":235,"url":364},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc4b6ba254e1a49ed91f2e268e6484011c540542a",{"type":235,"url":366},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Ffa7789d6c21222b85211755d822ef698d3b34e00",{"type":243,"url":244},{"type":243,"url":248},{"type":238,"url":370},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",[252,253],{"id":101,"slug":373,"dossier":44,"summary":374,"aliases":375,"sourceIds":378,"published":379,"modified":380,"checkedAt":7,"severity":381,"references":384,"versionKeys":405,"packageCount":32,"repositoryCount":156},"ghsa-926x-3r5x-gfhw-b7d12e65","LangChain has incomplete f-string validation in prompt templates",[376,377],"CVE-2026-40087","PYSEC-2026-2563",[101,377],"2026-04-08T21:51:32Z","2026-07-13T16:42:42.901211235Z",[382],{"type":231,"score":383},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[385,387,389,391,393,395,397,398,400,402,403],{"type":235,"url":386},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",{"type":238,"url":388},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40087",{"type":235,"url":390},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36612",{"type":235,"url":392},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36613",{"type":235,"url":394},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F6bab0ba3c12328008ddca3e0d54ff5a6151cd27b",{"type":235,"url":396},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Faf2ed47c6f008cdd551f3c0d87db3774c8dfe258",{"type":243,"url":244},{"type":235,"url":399},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.84",{"type":235,"url":401},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.28",{"type":243,"url":248},{"type":238,"url":404},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",[252,253,254],{"id":102,"slug":407,"dossier":44,"summary":408,"aliases":409,"sourceIds":412,"published":413,"modified":414,"checkedAt":7,"severity":415,"references":418,"versionKeys":439,"packageCount":32,"repositoryCount":166},"ghsa-c67j-w6g6-q2cm-a4c5c0cf","LangChain serialization injection vulnerability enables secret extraction in dumps\u002Floads APIs",[410,411],"CVE-2025-68664","PYSEC-2026-373",[102,411],"2025-12-23T18:46:13Z","2026-07-02T13:00:05.018724776Z",[416],{"type":231,"score":417},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:L\u002FA:N",[419,421,423,425,427,429,431,432,434,436,437],{"type":235,"url":420},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",{"type":238,"url":422},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68664",{"type":235,"url":424},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34455",{"type":235,"url":426},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34458",{"type":235,"url":428},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8",{"type":235,"url":430},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fd9ec4c5cc78960abd37da79b0250f5642e6f0ce6",{"type":243,"url":244},{"type":235,"url":433},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.81",{"type":235,"url":435},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.5",{"type":243,"url":248},{"type":238,"url":438},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",[252,253],{"id":103,"slug":441,"dossier":44,"summary":442,"aliases":443,"sourceIds":446,"published":447,"modified":448,"checkedAt":7,"severity":449,"references":452,"versionKeys":460,"packageCount":32,"repositoryCount":166},"ghsa-fv5p-p927-qmxr-2692dd04","LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass",[444,445],"CVE-2026-41481","PYSEC-2026-77",[103,445],"2026-04-16T22:53:32Z","2026-06-06T01:15:07.890699366Z",[450],{"type":231,"score":451},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[453,455,457,458],{"type":238,"url":454},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-fv5p-p927-qmxr",{"type":238,"url":456},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41481",{"type":243,"url":244},{"type":235,"url":459},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain-text-splitters\u002FPYSEC-2026-77.yaml",[461,462],"pypi:langchain-text-splitters@0.3.2","pypi:langchain-text-splitters@1.1.0",{"id":104,"slug":464,"dossier":44,"summary":465,"aliases":466,"sourceIds":470,"published":471,"modified":472,"checkedAt":7,"severity":473,"references":478,"versionKeys":487,"packageCount":32,"repositoryCount":34},"ghsa-gr75-jv2w-4656-a5b8c61e","LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders",[467,468,469],"CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556",[104,468],"2026-06-16T15:03:14Z","2026-08-07T08:11:57.170704540Z",[474,476],{"type":231,"score":475},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":231,"score":477},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[479,481,483,486],{"type":238,"url":480},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-gr75-jv2w-4656",{"type":238,"url":482},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55443",{"type":484,"url":485},"FIX","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fdcaf7795a3e6590af55c3ff7bda6add6355e9ea6",{"type":243,"url":244},[286,287,488],"pypi:langchain@1.2.6",{"id":105,"slug":490,"dossier":44,"summary":491,"aliases":492,"sourceIds":495,"published":496,"modified":497,"checkedAt":7,"severity":498,"references":503,"versionKeys":516,"packageCount":32,"repositoryCount":32},"ghsa-jw8x-6495-233v-cb32b711","scikit-learn sensitive data leakage vulnerability",[493,494],"CVE-2024-5206","PYSEC-2024-110",[105,494],"2024-06-06T19:16:00Z","2026-06-10T17:02:43.910139851Z",[499,501],{"type":231,"score":500},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":231,"score":502},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[504,506,508,510,512,514],{"type":238,"url":505},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-5206",{"type":484,"url":507},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn\u002Fcommit\u002F70ca21f106b603b611da73012c9ade7cd8e438b8",{"type":235,"url":509},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fscikit-learn\u002FPYSEC-2024-110.yaml",{"type":243,"url":511},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn",{"type":235,"url":513},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F14bc0917-a85b-4106-a170-d09d5191517c",{"type":238,"url":515},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jw8x-6495-233v",[517],"pypi:scikit-learn@1.3.2",{"id":106,"slug":519,"dossier":44,"summary":520,"aliases":521,"sourceIds":524,"published":525,"modified":526,"checkedAt":7,"severity":527,"references":530,"versionKeys":544,"packageCount":32,"repositoryCount":32},"ghsa-m42m-m8cr-8m58-f064d587","LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing",[522,523],"CVE-2025-6985","PYSEC-2026-1520",[106,523],"2025-10-06T18:31:07Z","2026-07-07T17:56:17.555935519Z",[528],{"type":231,"score":529},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[531,533,535,537,538,540,542],{"type":238,"url":532},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6985",{"type":235,"url":534},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F31819",{"type":235,"url":536},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F43eef435505a1c907227b724c0c760ad5fc01790",{"type":243,"url":244},{"type":235,"url":539},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fcf78abbb-df3b-43de-b6ee-132b73ff8331",{"type":243,"url":541},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-text-splitters",{"type":238,"url":543},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-m42m-m8cr-8m58",[461],{"id":107,"slug":546,"dossier":44,"summary":547,"aliases":548,"sourceIds":551,"published":552,"modified":553,"checkedAt":7,"severity":554,"references":556,"versionKeys":571,"packageCount":32,"repositoryCount":156},"ghsa-pc6w-59fv-rh23-cab9cb2f","Langchain Community Vulnerable to XML External Entity (XXE) Attacks",[549,550],"CVE-2025-6984","PYSEC-2026-1515",[107,550],"2025-09-04T12:30:42Z","2026-07-07T17:56:45.822570559Z",[555],{"type":231,"score":529},[557,559,561,563,565,567,569],{"type":238,"url":558},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6984",{"type":235,"url":560},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community\u002Fcommit\u002Fe842452108089524e22c3a2ced851c021884556f",{"type":243,"url":562},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community",{"type":235,"url":564},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fblob\u002Fd79b5813a0b3b243c612b77013768995e46c4337\u002Flibs\u002Flangchain\u002Flangchain\u002Fdocument_loaders\u002Fevernote.py#L1-L23",{"type":235,"url":566},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fa6b521cf-258c-41c0-9edb-d8ef976abb2a",{"type":243,"url":568},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-community",{"type":238,"url":570},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pc6w-59fv-rh23",[317,572,573],"pypi:langchain-community@0.3.5","pypi:langchain-community@0.3.7",{"id":108,"slug":575,"dossier":44,"summary":576,"aliases":577,"sourceIds":580,"published":581,"modified":582,"checkedAt":7,"severity":583,"references":586,"versionKeys":595,"packageCount":32,"repositoryCount":156},"ghsa-pjwx-r37v-7724-2297a72a","LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists",[578,579],"CVE-2026-44843","PYSEC-2026-2564",[108,579],"2026-05-08T23:07:32Z","2026-07-13T16:42:39.210995356Z",[584],{"type":231,"score":585},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[587,589,591,592,593],{"type":235,"url":588},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",{"type":238,"url":590},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44843",{"type":243,"url":244},{"type":243,"url":248},{"type":238,"url":594},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",[252,253,254],{"id":109,"slug":597,"dossier":44,"summary":598,"aliases":599,"sourceIds":602,"published":603,"modified":604,"checkedAt":7,"severity":605,"references":608,"versionKeys":623,"packageCount":32,"repositoryCount":32},"ghsa-q25c-c977-4cmh-8e74e348","Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever",[600,601],"CVE-2024-3095","PYSEC-2026-1516",[109,601],"2024-06-06T21:30:36Z","2026-07-07T17:57:27.127785500Z",[606],{"type":231,"score":607},"CVSS:3.0\u002FAV:P\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[609,611,613,615,616,618,620,621],{"type":238,"url":610},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-3095",{"type":235,"url":612},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F24451",{"type":235,"url":614},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F604dfe2d99246b0c09f047c604f0c63eafba31e7",{"type":243,"url":244},{"type":235,"url":617},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-community%3D%3D0.2.9",{"type":235,"url":619},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fe62d4895-2901-405b-9559-38276b6a5273",{"type":243,"url":568},{"type":238,"url":622},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q25c-c977-4cmh",[317],{"id":110,"slug":625,"dossier":44,"summary":626,"aliases":627,"sourceIds":630,"published":631,"modified":632,"checkedAt":7,"severity":633,"references":636,"versionKeys":658,"packageCount":32,"repositoryCount":156},"ghsa-qh6h-p6c9-ff54-caf42ff5","LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions",[628,629],"CVE-2026-34070","PYSEC-2026-2193",[110,629],"2026-03-27T19:45:00Z","2026-07-13T07:26:33.913236655Z",[634],{"type":231,"score":635},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[637,640,642,644,645,647,649,651,653,655],{"type":638,"url":639},"EVIDENCE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-qh6h-p6c9-ff54",{"type":238,"url":641},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34070",{"type":484,"url":643},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F27add913474e01e33bededf4096151130ba0d47c",{"type":243,"url":244},{"type":238,"url":646},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core==1.2.22",{"type":235,"url":648},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-34070",{"type":235,"url":650},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-34070.json",{"type":238,"url":652},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24766",{"type":238,"url":654},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37275",{"type":656,"url":657},"REPORT","https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2453287",[252,253,254],{"id":111,"slug":660,"dossier":44,"summary":661,"aliases":662,"sourceIds":665,"published":666,"modified":667,"checkedAt":7,"severity":668,"references":671,"versionKeys":679,"packageCount":32,"repositoryCount":34},"ghsa-r7w7-9xr2-qq2r-7a3a0a91","langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding",[663,664],"CVE-2026-41488","PYSEC-2026-76",[111,664],"2026-04-16T23:00:12Z","2026-06-06T01:15:07.912179267Z",[669],{"type":231,"score":670},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[672,674,676,677],{"type":238,"url":673},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-r7w7-9xr2-qq2r",{"type":238,"url":675},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41488",{"type":243,"url":244},{"type":235,"url":678},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain-openai\u002FPYSEC-2026-76.yaml",[680,681,682,683],"pypi:langchain-openai@0.2.8","pypi:langchain-openai@0.3.0","pypi:langchain-openai@1.1.7","pypi:langchain-openai@1.1.9",{"id":113,"slug":685,"dossier":44,"summary":136,"aliases":686,"sourceIds":690,"published":691,"modified":692,"checkedAt":7,"severity":693,"references":696,"versionKeys":700,"packageCount":32,"repositoryCount":32},"pysec-2024-323-1dd96856",[687,688,689],"CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514",[113],"2024-09-17T12:15:02.977Z","2026-07-13T07:26:23.643495355Z",[694],{"type":231,"score":695},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[697,698],{"type":484,"url":614},{"type":638,"url":699},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ffa3a2753-57c3-4e08-a176-d7a3ffda28fe",[286],1786635286799]