[{"data":1,"prerenderedAt":633},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-4166":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":42,"summary":61,"kind":77,"entity":78,"evidence":116,"related":124},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-07-20T14:37:29.537Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-07-20T14:36:19.763Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.28.0","2026-02-20T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":31,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":36,"parsedFileCount":37,"parseErrorCount":32,"unsupportedFileCount":38,"evaluatedVersionCount":39,"metadataResolvedCount":40,"metadataNotFoundCount":41,"osvEvaluatedVersionCount":39,"codeRadarRepositoryCount":30},30,29,1,17,4,20,33,32,0,4205,4191,14,{"componentParserSchemaVersion":43,"candidateBoundary":44,"resolvedVersionBoundary":45,"manifestRangesResolved":46,"latestVersionSubstitution":46,"containerTagsVulnerabilityChecked":46,"osvClaim":47,"depsDevLicenseSemantics":48,"providerSemantics":49,"generativeAiUsed":46,"scoreUsed":46,"treeEntryCeiling":50,"fileByteCeiling":51,"uniqueVersionCeiling":52,"observedFormats":53},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,5000,[54,55,56,57,58,59,60],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":62,"aiPackageCount":63,"resolvedComponentCount":64,"resolvedVersionCount":39,"providerExposureRepositoryCount":65,"licenseExpressionCount":66,"knownLicensePackageCount":67,"unknownLicensePackageCount":68,"advisoryCount":69,"matchedAdvisoryRepositoryCount":70,"topPackage":71},2831,41,7181,7,57,2796,35,572,25,{"id":72,"slug":73,"label":74,"repositoryCount":75,"repositoryShare":76},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",18,0.6,"repository",{"id":79,"slug":80,"gitlabProjectId":81,"name":82,"pathWithNamespace":83,"description":84,"webUrl":85,"commitSha":86,"commitUrl":87,"lastActivityAt":88,"headCommittedAt":89,"tree":90,"files":93,"resolvedComponentCount":94,"artifactResolvedComponentCount":38,"exactManifestPinCount":94,"packageCount":94,"ecosystems":95,"aiPackageCount":94,"licenseExpressionCount":32,"unknownLicensePackageCount":38,"advisoryIds":97,"advisoryCount":114,"providers":115},"opencode:4166","opencode-4166",4166,"ai-legal-graph","iorb\u002Fai-legal-graph",null,"https:\u002F\u002Fgitlab.opencode.de\u002Fiorb\u002Fai-legal-graph","8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be","https:\u002F\u002Fgitlab.opencode.de\u002Fiorb\u002Fai-legal-graph\u002F-\u002Fcommit\u002F8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be","2025-04-10T15:29:54.353Z","2025-03-31T12:14:45.000Z",{"complete":91,"entryCount":92,"truncated":46},true,234,[],8,[96],"pypi",[98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113],"GHSA-2g6r-c272-w58r","GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-5chr-fjjv-38qv","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-c67j-w6g6-q2cm","GHSA-g48c-2wqr-h844","GHSA-gr75-jv2w-4656","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-q25c-c977-4cmh","GHSA-qh6h-p6c9-ff54","GHSA-w39p-vh2g-g8g5","PYSEC-2024-115","PYSEC-2024-323",16,[],{"files":117,"occurrenceCount":94},[118],{"path":119,"kind":120,"sourceUrl":121,"commitSha":86,"blobSha":122,"state":123,"componentCount":94},"requirements.txt","exact-manifest-pin","https:\u002F\u002Fgitlab.opencode.de\u002Fiorb\u002Fai-legal-graph\u002F-\u002Fblob\u002F8c26aa4fed1fcb1be4ecfbbf745144dbf812e4be\u002Frequirements.txt","eb8e9a474c655bc81e1a5841cf757dec75775529","parsed",{"packages":125,"vulnerabilities":199},[126,136,145,154,164,173,182,191],{"id":127,"slug":128,"identity":129,"label":130,"aiRelevant":91,"provider":84,"advisoryCount":65,"licenseExpressions":131,"versions":133,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":135},"package:pypi:langchain-core","langchain-core-82117efb","pypi:langchain-core","LangChain Core",[132],"MIT",[134],"0.2.28",[119],{"id":137,"slug":138,"identity":139,"label":140,"aiRelevant":91,"provider":84,"advisoryCount":34,"licenseExpressions":141,"versions":142,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":144},"package:pypi:langchain-community","langchain-community-b296254c","pypi:langchain-community","LangChain Community",[132],[143],"0.2.7",[119],{"id":146,"slug":147,"identity":148,"label":149,"aiRelevant":91,"provider":84,"advisoryCount":150,"licenseExpressions":151,"versions":152,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":153},"package:pypi:langchain","langchain-2b3b6a0b","pypi:langchain","LangChain",3,[132],[143],[119],{"id":155,"slug":156,"identity":157,"label":158,"aiRelevant":91,"provider":84,"advisoryCount":159,"licenseExpressions":160,"versions":161,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":163},"package:pypi:langgraph","langgraph-6c1c645e","pypi:langgraph","LangGraph",2,[132],[162],"0.1.1",[119],{"id":165,"slug":166,"identity":167,"label":168,"aiRelevant":91,"provider":84,"advisoryCount":38,"licenseExpressions":169,"versions":170,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":172},"package:pypi:langchain-experimental","langchain-experimental-7a9ed002","pypi:langchain-experimental","LangChain · Experimental",[132],[171],"0.0.63",[119],{"id":174,"slug":175,"identity":176,"label":177,"aiRelevant":91,"provider":84,"advisoryCount":38,"licenseExpressions":178,"versions":179,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":181},"package:pypi:langchain-groq","langchain-groq-aed894e4","pypi:langchain-groq","LangChain · Groq",[132],[180],"0.1.5",[119],{"id":183,"slug":184,"identity":185,"label":186,"aiRelevant":91,"provider":84,"advisoryCount":38,"licenseExpressions":187,"versions":188,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":190},"package:pypi:langchain-huggingface","langchain-huggingface-89b06dab","pypi:langchain-huggingface","LangChain · Hugging Face",[132],[189],"0.0.3",[119],{"id":192,"slug":193,"identity":194,"label":195,"aiRelevant":91,"provider":84,"advisoryCount":38,"licenseExpressions":196,"versions":197,"dossier":91,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":198},"package:pypi:langchain-ollama","langchain-ollama-c606221f","pypi:langchain-ollama","LangChain · Ollama",[132],[162],[119],[200,234,268,297,325,351,385,419,446,473,502,524,552,587,616],{"id":98,"slug":201,"dossier":46,"summary":202,"aliases":203,"sourceIds":206,"published":207,"modified":208,"checkedAt":7,"severity":209,"references":213,"versionKeys":231,"packageCount":32,"repositoryCount":159},"ghsa-2g6r-c272-w58r-4bbbcb01","LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages",[204,205],"CVE-2026-26013","PYSEC-2026-2562",[98,205],"2026-02-11T14:23:13Z","2026-07-13T16:43:30.756724986Z",[210],{"type":211,"score":212},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[214,217,220,222,225,227,229],{"type":215,"url":216},"WEB","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",{"type":218,"url":219},"ADVISORY","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-26013",{"type":215,"url":221},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F2b4b1dc29a833d4053deba4c2b77a3848c834565",{"type":223,"url":224},"PACKAGE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain",{"type":215,"url":226},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.11",{"type":223,"url":228},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-core",{"type":218,"url":230},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",[232,233],"pypi:langchain-core@0.2.28","pypi:langchain-core@1.2.7",{"id":99,"slug":235,"dossier":46,"summary":236,"aliases":237,"sourceIds":242,"published":243,"modified":244,"checkedAt":7,"severity":245,"references":248,"versionKeys":263,"packageCount":150,"repositoryCount":150},"ghsa-3644-q5cj-c5c7-4c578cf2","LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning",[238,239,240,241],"CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582",[99,239,240,241],"2026-05-13T15:29:30Z","2026-07-13T16:43:39.736848907Z",[246],{"type":211,"score":247},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[249,251,253,255,257,259,261],{"type":215,"url":250},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk\u002Fsecurity\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":218,"url":252},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45134",{"type":223,"url":254},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk",{"type":223,"url":256},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain",{"type":218,"url":258},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":223,"url":260},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-classic",{"type":223,"url":262},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangsmith",[264,265,266,267],"pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4",{"id":100,"slug":269,"dossier":46,"summary":270,"aliases":271,"sourceIds":274,"published":275,"modified":276,"checkedAt":7,"severity":277,"references":283,"versionKeys":295,"packageCount":32,"repositoryCount":32},"ghsa-45pg-36p6-83v9-9505da12","Langchain SQL Injection vulnerability",[272,112,273],"CVE-2024-8309","PYSEC-2026-1507",[100],"2024-10-29T15:32:05Z","2026-07-07T17:57:12.591755527Z",[278,280],{"type":211,"score":279},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":281,"score":282},"CVSS_V4","CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[284,286,288,290,291,293],{"type":218,"url":285},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-8309",{"type":215,"url":287},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F64c317eba05fbac0c6a6fc5aa192bc0d7130972e",{"type":215,"url":289},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc2a3021bb0c5f54649d380b42a0684ca5778c255",{"type":223,"url":224},{"type":215,"url":292},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain\u002FPYSEC-2024-115.yaml",{"type":215,"url":294},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5",[296],"pypi:langchain-community@0.2.7",{"id":101,"slug":298,"dossier":46,"summary":299,"aliases":300,"sourceIds":303,"published":304,"modified":305,"checkedAt":7,"severity":306,"references":309,"versionKeys":324,"packageCount":32,"repositoryCount":32},"ghsa-5chr-fjjv-38qv-5f3dd755","langchain-core allows unauthorized users to read arbitrary files from the host file system",[301,302],"CVE-2024-10940","PYSEC-2026-1517",[101,302],"2025-03-20T12:32:41Z","2026-07-07T17:56:35.905913395Z",[307],{"type":211,"score":308},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[310,312,314,316,318,319,321,322],{"type":218,"url":311},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-10940",{"type":215,"url":313},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F7d481f10102f43559cc57bcad7eba291067939ee",{"type":215,"url":315},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc1e742347f9701aadba8920e4d1f79a636e50b68",{"type":215,"url":317},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fe711034713259ae448981bc0fd1d7a5671499c31",{"type":223,"url":224},{"type":215,"url":320},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fbe1ee1cb-2147-4ff4-a57b-b6045271cf27",{"type":223,"url":228},{"type":218,"url":323},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5chr-fjjv-38qv",[232],{"id":102,"slug":326,"dossier":46,"summary":327,"aliases":328,"sourceIds":331,"published":332,"modified":333,"checkedAt":7,"severity":334,"references":337,"versionKeys":350,"packageCount":32,"repositoryCount":32},"ghsa-6qv9-48xg-fc7f-6f0bc426","LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates",[329,330],"CVE-2025-65106","PYSEC-2026-1518",[102,330],"2025-11-20T17:42:12Z","2026-07-07T17:57:16.939269197Z",[335],{"type":281,"score":336},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[338,340,342,344,346,347,348],{"type":215,"url":339},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",{"type":218,"url":341},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-65106",{"type":215,"url":343},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc4b6ba254e1a49ed91f2e268e6484011c540542a",{"type":215,"url":345},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Ffa7789d6c21222b85211755d822ef698d3b34e00",{"type":223,"url":224},{"type":223,"url":228},{"type":218,"url":349},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",[232],{"id":103,"slug":352,"dossier":46,"summary":353,"aliases":354,"sourceIds":357,"published":358,"modified":359,"checkedAt":7,"severity":360,"references":363,"versionKeys":384,"packageCount":32,"repositoryCount":159},"ghsa-926x-3r5x-gfhw-b7d12e65","LangChain has incomplete f-string validation in prompt templates",[355,356],"CVE-2026-40087","PYSEC-2026-2563",[103,356],"2026-04-08T21:51:32Z","2026-07-13T16:42:42.901211235Z",[361],{"type":211,"score":362},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[364,366,368,370,372,374,376,377,379,381,382],{"type":215,"url":365},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",{"type":218,"url":367},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40087",{"type":215,"url":369},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36612",{"type":215,"url":371},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36613",{"type":215,"url":373},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F6bab0ba3c12328008ddca3e0d54ff5a6151cd27b",{"type":215,"url":375},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Faf2ed47c6f008cdd551f3c0d87db3774c8dfe258",{"type":223,"url":224},{"type":215,"url":378},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.84",{"type":215,"url":380},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.28",{"type":223,"url":228},{"type":218,"url":383},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",[232,233],{"id":104,"slug":386,"dossier":46,"summary":387,"aliases":388,"sourceIds":391,"published":392,"modified":393,"checkedAt":7,"severity":394,"references":397,"versionKeys":418,"packageCount":32,"repositoryCount":32},"ghsa-c67j-w6g6-q2cm-a4c5c0cf","LangChain serialization injection vulnerability enables secret extraction in dumps\u002Floads APIs",[389,390],"CVE-2025-68664","PYSEC-2026-373",[104,390],"2025-12-23T18:46:13Z","2026-07-02T13:00:05.018724776Z",[395],{"type":211,"score":396},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:L\u002FA:N",[398,400,402,404,406,408,410,411,413,415,416],{"type":215,"url":399},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",{"type":218,"url":401},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68664",{"type":215,"url":403},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34455",{"type":215,"url":405},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34458",{"type":215,"url":407},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8",{"type":215,"url":409},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fd9ec4c5cc78960abd37da79b0250f5642e6f0ce6",{"type":223,"url":224},{"type":215,"url":412},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.81",{"type":215,"url":414},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.5",{"type":223,"url":228},{"type":218,"url":417},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",[232],{"id":105,"slug":420,"dossier":46,"summary":421,"aliases":422,"sourceIds":425,"published":426,"modified":427,"checkedAt":7,"severity":428,"references":433,"versionKeys":442,"packageCount":32,"repositoryCount":150},"ghsa-g48c-2wqr-h844-48f35247","LangGraph checkpoint loading has unsafe msgpack deserialization",[423,424],"CVE-2026-28277","PYSEC-2026-83",[105,424],"2026-03-05T20:16:15.677Z","2026-06-06T01:00:08.116125988Z",[429,431],{"type":211,"score":430},"CVSS:3.1\u002FAV:A\u002FAC:L\u002FPR:H\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",{"type":211,"score":432},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:H\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[434,436,438,440],{"type":218,"url":435},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flanggraph\u002Fsecurity\u002Fadvisories\u002FGHSA-g48c-2wqr-h844",{"type":218,"url":437},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-28277",{"type":223,"url":439},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flanggraph",{"type":215,"url":441},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flanggraph\u002FPYSEC-2026-83.yaml",[443,444,445],"pypi:langgraph@0.1.1","pypi:langgraph@0.3.21","pypi:langgraph@1.0.6",{"id":106,"slug":447,"dossier":46,"summary":448,"aliases":449,"sourceIds":453,"published":454,"modified":455,"checkedAt":7,"severity":456,"references":461,"versionKeys":470,"packageCount":32,"repositoryCount":34},"ghsa-gr75-jv2w-4656-a5b8c61e","LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders",[450,451,452],"CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556",[106,451],"2026-06-16T15:03:14Z","2026-07-13T16:43:09.845932020Z",[457,459],{"type":211,"score":458},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":211,"score":460},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[462,464,466,469],{"type":218,"url":463},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-gr75-jv2w-4656",{"type":218,"url":465},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55443",{"type":467,"url":468},"FIX","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fdcaf7795a3e6590af55c3ff7bda6add6355e9ea6",{"type":223,"url":224},[265,266,471,472],"pypi:langchain@1.2.6","pypi:langchain@1.3.8",{"id":107,"slug":474,"dossier":46,"summary":475,"aliases":476,"sourceIds":479,"published":480,"modified":481,"checkedAt":7,"severity":482,"references":485,"versionKeys":500,"packageCount":32,"repositoryCount":159},"ghsa-pc6w-59fv-rh23-cab9cb2f","Langchain Community Vulnerable to XML External Entity (XXE) Attacks",[477,478],"CVE-2025-6984","PYSEC-2026-1515",[107,478],"2025-09-04T12:30:42Z","2026-07-07T17:56:45.822570559Z",[483],{"type":211,"score":484},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[486,488,490,492,494,496,498],{"type":218,"url":487},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6984",{"type":215,"url":489},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community\u002Fcommit\u002Fe842452108089524e22c3a2ced851c021884556f",{"type":223,"url":491},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community",{"type":215,"url":493},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fblob\u002Fd79b5813a0b3b243c612b77013768995e46c4337\u002Flibs\u002Flangchain\u002Flangchain\u002Fdocument_loaders\u002Fevernote.py#L1-L23",{"type":215,"url":495},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fa6b521cf-258c-41c0-9edb-d8ef976abb2a",{"type":223,"url":497},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-community",{"type":218,"url":499},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pc6w-59fv-rh23",[296,501],"pypi:langchain-community@0.3.7",{"id":108,"slug":503,"dossier":46,"summary":504,"aliases":505,"sourceIds":508,"published":509,"modified":510,"checkedAt":7,"severity":511,"references":514,"versionKeys":523,"packageCount":32,"repositoryCount":159},"ghsa-pjwx-r37v-7724-2297a72a","LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists",[506,507],"CVE-2026-44843","PYSEC-2026-2564",[108,507],"2026-05-08T23:07:32Z","2026-07-13T16:42:39.210995356Z",[512],{"type":211,"score":513},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[515,517,519,520,521],{"type":215,"url":516},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",{"type":218,"url":518},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44843",{"type":223,"url":224},{"type":223,"url":228},{"type":218,"url":522},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",[232,233],{"id":109,"slug":525,"dossier":46,"summary":526,"aliases":527,"sourceIds":530,"published":531,"modified":532,"checkedAt":7,"severity":533,"references":536,"versionKeys":551,"packageCount":32,"repositoryCount":32},"ghsa-q25c-c977-4cmh-8e74e348","Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever",[528,529],"CVE-2024-3095","PYSEC-2026-1516",[109,529],"2024-06-06T21:30:36Z","2026-07-07T17:57:27.127785500Z",[534],{"type":211,"score":535},"CVSS:3.0\u002FAV:P\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[537,539,541,543,544,546,548,549],{"type":218,"url":538},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-3095",{"type":215,"url":540},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F24451",{"type":215,"url":542},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F604dfe2d99246b0c09f047c604f0c63eafba31e7",{"type":223,"url":224},{"type":215,"url":545},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-community%3D%3D0.2.9",{"type":215,"url":547},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fe62d4895-2901-405b-9559-38276b6a5273",{"type":223,"url":497},{"type":218,"url":550},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q25c-c977-4cmh",[296],{"id":110,"slug":553,"dossier":46,"summary":554,"aliases":555,"sourceIds":558,"published":559,"modified":560,"checkedAt":7,"severity":561,"references":564,"versionKeys":586,"packageCount":32,"repositoryCount":159},"ghsa-qh6h-p6c9-ff54-caf42ff5","LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions",[556,557],"CVE-2026-34070","PYSEC-2026-2193",[110,557],"2026-03-27T19:45:00Z","2026-07-13T07:26:33.913236655Z",[562],{"type":211,"score":563},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[565,568,570,572,573,575,577,579,581,583],{"type":566,"url":567},"EVIDENCE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-qh6h-p6c9-ff54",{"type":218,"url":569},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34070",{"type":467,"url":571},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F27add913474e01e33bededf4096151130ba0d47c",{"type":223,"url":224},{"type":218,"url":574},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core==1.2.22",{"type":215,"url":576},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-34070",{"type":215,"url":578},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-34070.json",{"type":218,"url":580},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24766",{"type":218,"url":582},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37275",{"type":584,"url":585},"REPORT","https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2453287",[232,233],{"id":111,"slug":588,"dossier":46,"summary":589,"aliases":590,"sourceIds":594,"published":595,"modified":596,"checkedAt":7,"severity":597,"references":602,"versionKeys":614,"packageCount":159,"repositoryCount":159},"ghsa-w39p-vh2g-g8g5-47880dfe","LangGraph SDK has unsafe URL path construction",[591,592,593],"CVE-2026-48776","PYSEC-2026-2194","PYSEC-2026-2575",[111,592,593],"2026-06-17T10:55:15.113Z","2026-07-13T16:42:27.619863658Z",[598,600],{"type":211,"score":599},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:N",{"type":211,"score":601},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:N",[603,605,607,608,610,612],{"type":215,"url":604},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flanggraph\u002Fsecurity\u002Fadvisories\u002FGHSA-w39p-vh2g-g8g5",{"type":218,"url":606},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-48776",{"type":223,"url":439},{"type":215,"url":609},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flanggraph\u002Freleases\u002Ftag\u002Fsdk%3D%3D0.3.15",{"type":223,"url":611},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flanggraph-sdk",{"type":218,"url":613},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-w39p-vh2g-g8g5",[615,443],"pypi:langgraph-sdk@0.3.3",{"id":113,"slug":617,"dossier":46,"summary":84,"aliases":618,"sourceIds":622,"published":623,"modified":624,"checkedAt":7,"severity":625,"references":628,"versionKeys":632,"packageCount":32,"repositoryCount":32},"pysec-2024-323-1dd96856",[619,620,621],"CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514",[113],"2024-09-17T12:15:02.977Z","2026-07-13T07:26:23.643495355Z",[626],{"type":211,"score":627},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[629,630],{"type":467,"url":542},{"type":566,"url":631},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ffa3a2753-57c3-4e08-a176-d7a3ffda28fe",[265],1784558562347]