CVE-2025-65106 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability…
High CVSS: 8.3

CVE-2025-65106

LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template system that allows attackers to access Python object internals through template syntax. This vulnerability affects applications that accept untrusted template strings (not just template variables) in ChatPromptTemplate and related prompt template classes. This issue has been patched in versions 0.3.80 and 1.0.7.
Vendor
-
Product
-
CWE
CWE-1336
Yayın Tarihi
2025-11-21 22:16:32
Güncelleme
2025-11-25 22:16:42
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar