[{"data":1,"prerenderedAt":704},["ShallowReactive",2],{"ki-abhaengigkeitsatlas-repository-opencode-12475":3},{"schemaVersion":4,"dataset":5,"parserVersion":6,"generatedAt":7,"trackingSince":8,"source":9,"coverage":29,"methodology":43,"summary":62,"kind":76,"entity":77,"evidence":122,"related":130},"ki-abhaengigkeitsatlas\u002Fv1","german-public-sector-ai-dependency-atlas","1","2026-09-30T08:36:30.871Z","2026-07-18T21:20:30.334Z",{"codeRadar":10,"openCode":15,"depsDev":18,"osv":21,"spdx":24},{"dataset":11,"generatedAt":12,"parserVersion":13,"url":14},"german-public-sector-ai-code-radar","2026-09-30T08:33:18.305Z","3","https:\u002F\u002Fi6eal.de\u002Ftools\u002Fki-code-radar\u002F",{"label":16,"url":17},"openCode GitLab","https:\u002F\u002Fgitlab.opencode.de\u002F",{"label":19,"url":20},"deps.dev API v3","https:\u002F\u002Fdocs.deps.dev\u002Fapi\u002Fv3\u002F",{"label":22,"url":23},"OSV API","https:\u002F\u002Fgoogle.github.io\u002Fosv.dev\u002Fapi\u002F",{"label":25,"url":26,"version":27,"releaseDate":28},"SPDX License List","https:\u002F\u002Fspdx.org\u002Flicenses\u002F","3.29.0","2026-09-16T00:00:00Z",{"repositoryCount":30,"completeTreeCount":31,"incompleteTreeCount":32,"lockfileRepositoryCount":33,"sbomRepositoryCount":34,"artifactRepositoryCount":35,"resolvedRepositoryCount":36,"resolvedArtifactRepositoryCount":35,"dependencyFileCount":37,"parsedFileCount":38,"parseErrorCount":32,"unsupportedFileCount":39,"evaluatedVersionCount":40,"metadataResolvedCount":41,"metadataNotFoundCount":42,"osvEvaluatedVersionCount":40,"codeRadarRepositoryCount":30},43,42,1,23,4,26,40,38,37,0,4104,4093,11,{"componentParserSchemaVersion":44,"candidateBoundary":45,"resolvedVersionBoundary":46,"manifestRangesResolved":47,"latestVersionSubstitution":47,"containerTagsVulnerabilityChecked":47,"osvClaim":48,"depsDevLicenseSemantics":49,"providerSemantics":50,"generativeAiUsed":47,"scoreUsed":47,"treeEntryCeiling":51,"fileByteCeiling":52,"uniqueVersionCeiling":53,"observedFormats":54},"ki-dependency-atlas-components\u002Fv1","repositories_with_exact_ai_code_evidence","exact_lockfile_or_sbom_component_or_exact_double_equals_manifest_pin",false,"osv_matched_observed_resolved_package_version_at_collection_time","spdx_expressions_as_reported_without_inferred_compatibility","package_interface_presence_not_api_configuration_procurement_or_use",2500,5242880,8000,[55,56,57,58,59,60,61],"package-lock.json \u002F npm-shrinkwrap.json","uv.lock","poetry.lock","Pipfile.lock","CycloneDX JSON","SPDX JSON or YAML","exact == manifest pins",{"repositoryCount":30,"packageCount":63,"aiPackageCount":64,"resolvedComponentCount":65,"resolvedVersionCount":40,"providerExposureRepositoryCount":66,"licenseExpressionCount":67,"knownLicensePackageCount":68,"unknownLicensePackageCount":69,"advisoryCount":70,"matchedAdvisoryRepositoryCount":38,"topPackage":71},2460,50,7146,9,55,2426,34,822,{"id":72,"slug":73,"label":74,"repositoryCount":33,"repositoryShare":75},"package:pypi:openai","openai-0dd26ac5","OpenAI SDK",0.5348837209302325,"repository",{"id":78,"slug":79,"gitlabProjectId":80,"name":81,"pathWithNamespace":82,"description":83,"webUrl":84,"commitSha":85,"commitUrl":86,"lastActivityAt":87,"headCommittedAt":88,"tree":89,"files":92,"resolvedComponentCount":66,"artifactResolvedComponentCount":39,"exactManifestPinCount":66,"packageCount":66,"ecosystems":93,"aiPackageCount":66,"licenseExpressionCount":34,"unknownLicensePackageCount":39,"advisoryIds":95,"advisoryCount":114,"providers":115},"opencode:12475","opencode-12475",12475,"ai-sr-litscreen","OpenBfS\u002Fkemf\u002Fai-sr-litscreen","Programmable large‑language‑model workflows for high‑sensitivity, cost‑efficient title and abstract screening in systematic reviews, including ready‑to‑run Jupyter notebooks for open‑source and OpenAI ‘mini’ models and example input templates.","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen","1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen\u002F-\u002Fcommit\u002F1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428","2026-08-13T12:13:52.094Z","2026-08-10T17:43:00.000Z",{"complete":90,"entryCount":91,"truncated":47},true,14,[],[94],"pypi",[96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113],"GHSA-2g6r-c272-w58r","GHSA-3644-q5cj-c5c7","GHSA-45pg-36p6-83v9","GHSA-5chr-fjjv-38qv","GHSA-6qv9-48xg-fc7f","GHSA-926x-3r5x-gfhw","GHSA-c67j-w6g6-q2cm","GHSA-fv5p-p927-qmxr","GHSA-gr75-jv2w-4656","GHSA-jw8x-6495-233v","GHSA-m42m-m8cr-8m58","GHSA-pc6w-59fv-rh23","GHSA-pjwx-r37v-7724","GHSA-q25c-c977-4cmh","GHSA-qh6h-p6c9-ff54","GHSA-r7w7-9xr2-qq2r","PYSEC-2024-115","PYSEC-2024-323",18,[116,119],{"id":117,"label":118},"openai","OpenAI",{"id":120,"label":121},"ollama","Ollama",{"files":123,"occurrenceCount":66},[124],{"path":125,"kind":126,"sourceUrl":127,"commitSha":85,"blobSha":128,"state":129,"componentCount":66},"requirements.txt","exact-manifest-pin","https:\u002F\u002Fgitlab.opencode.de\u002FOpenBfS\u002Fkemf\u002Fai-sr-litscreen\u002F-\u002Fblob\u002F1ccd1f9b7dc9c14fe21cabd193cd02f2d7c79428\u002Frequirements.txt","de2aedada3ed28288167bfa22e0b922d0a82b90f","parsed",{"packages":131,"vulnerabilities":221},[132,144,153,163,173,183,194,204,212],{"id":133,"slug":134,"identity":135,"label":136,"aiRelevant":90,"provider":137,"advisoryCount":138,"licenseExpressions":139,"versions":141,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":143},"package:pypi:langchain-core","langchain-core-82117efb","pypi:langchain-core","LangChain Core",null,7,[140],"MIT",[142],"0.3.45",[125],{"id":145,"slug":146,"identity":147,"label":148,"aiRelevant":90,"provider":137,"advisoryCount":34,"licenseExpressions":149,"versions":150,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":152},"package:pypi:langchain-community","langchain-community-b296254c","pypi:langchain-community","LangChain Community",[140],[151],"0.3.5",[125],{"id":154,"slug":155,"identity":156,"label":157,"aiRelevant":90,"provider":137,"advisoryCount":158,"licenseExpressions":159,"versions":160,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":162},"package:pypi:langchain","langchain-2b3b6a0b","pypi:langchain","LangChain",3,[140],[161],"0.3.7",[125],{"id":164,"slug":165,"identity":166,"label":167,"aiRelevant":90,"provider":137,"advisoryCount":168,"licenseExpressions":169,"versions":170,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":172},"package:pypi:langchain-text-splitters","langchain-text-splitters-0c057788","pypi:langchain-text-splitters","LangChain · Text Splitters",2,[140],[171],"0.3.2",[125],{"id":174,"slug":175,"identity":176,"label":177,"aiRelevant":90,"provider":178,"advisoryCount":32,"licenseExpressions":179,"versions":180,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":182},"package:pypi:langchain-openai","langchain-openai-4985188e","pypi:langchain-openai","LangChain OpenAI",{"id":117,"label":118},[140],[181],"0.3.0",[125],{"id":184,"slug":185,"identity":186,"label":187,"aiRelevant":90,"provider":137,"advisoryCount":32,"licenseExpressions":188,"versions":191,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":193},"package:pypi:scikit-learn","scikit-learn-ab0941d9","pypi:scikit-learn","scikit-learn",[189,190],"BSD-3-Clause","non-standard",[192],"1.3.2",[125],{"id":195,"slug":196,"identity":197,"label":198,"aiRelevant":90,"provider":199,"advisoryCount":39,"licenseExpressions":200,"versions":201,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":203},"package:pypi:ollama","ollama-0b25d881","pypi:ollama","Ollama SDK",{"id":120,"label":121},[140],[202],"0.3.3",[125],{"id":72,"slug":73,"identity":205,"label":74,"aiRelevant":90,"provider":206,"advisoryCount":39,"licenseExpressions":207,"versions":209,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":211},"pypi:openai",{"id":117,"label":118},[208],"Apache-2.0",[210],"1.78.1",[125],{"id":213,"slug":214,"identity":215,"label":216,"aiRelevant":90,"provider":137,"advisoryCount":39,"licenseExpressions":217,"versions":218,"dossier":90,"occurrenceCount":32,"directOccurrenceCount":32,"evidenceFiles":220},"package:pypi:langchain-ollama","langchain-ollama-c606221f","pypi:langchain-ollama","LangChain · Ollama",[140],[219],"0.2.0",[125],[222,258,292,321,349,375,409,443,466,492,521,548,577,599,627,662,687],{"id":96,"slug":223,"dossier":47,"summary":224,"aliases":225,"sourceIds":228,"published":229,"modified":230,"checkedAt":7,"severity":231,"references":235,"versionKeys":253,"packageCount":32,"repositoryCount":34},"ghsa-2g6r-c272-w58r-4bbbcb01","LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages",[226,227],"CVE-2026-26013","PYSEC-2026-2562",[96,227],"2026-02-11T14:23:13Z","2026-09-10T03:50:33.793703014Z",[232],{"type":233,"score":234},"CVSS_V3","CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:N\u002FI:N\u002FA:L",[236,239,242,244,247,249,251],{"type":237,"url":238},"WEB","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",{"type":240,"url":241},"ADVISORY","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-26013",{"type":237,"url":243},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F2b4b1dc29a833d4053deba4c2b77a3848c834565",{"type":245,"url":246},"PACKAGE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain",{"type":237,"url":248},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.11",{"type":245,"url":250},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-core",{"type":240,"url":252},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-2g6r-c272-w58r",[254,255,256,257],"pypi:langchain-core@0.2.28","pypi:langchain-core@0.3.45","pypi:langchain-core@0.3.65","pypi:langchain-core@1.2.7",{"id":97,"slug":259,"dossier":47,"summary":260,"aliases":261,"sourceIds":266,"published":267,"modified":268,"checkedAt":7,"severity":269,"references":272,"versionKeys":287,"packageCount":158,"repositoryCount":34},"ghsa-3644-q5cj-c5c7-4c578cf2","LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning",[262,263,264,265],"CVE-2026-45134","PYSEC-2026-2555","PYSEC-2026-2560","PYSEC-2026-2582",[97,263,264,265],"2026-05-13T15:29:30Z","2026-09-10T03:51:04.416695616Z",[270],{"type":233,"score":271},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[273,275,277,279,281,283,285],{"type":237,"url":274},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk\u002Fsecurity\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":240,"url":276},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-45134",{"type":245,"url":278},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangsmith-sdk",{"type":245,"url":280},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain",{"type":240,"url":282},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-3644-q5cj-c5c7",{"type":245,"url":284},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-classic",{"type":245,"url":286},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangsmith",[288,289,290,291],"pypi:langchain-classic@1.0.1","pypi:langchain@0.2.7","pypi:langchain@0.3.7","pypi:langsmith@0.6.4",{"id":98,"slug":293,"dossier":47,"summary":294,"aliases":295,"sourceIds":298,"published":299,"modified":300,"checkedAt":7,"severity":301,"references":307,"versionKeys":319,"packageCount":32,"repositoryCount":32},"ghsa-45pg-36p6-83v9-9505da12","Langchain SQL Injection vulnerability",[296,112,297],"CVE-2024-8309","PYSEC-2026-1507",[98],"2024-10-29T15:32:05Z","2026-07-07T17:57:12.591755527Z",[302,304],{"type":233,"score":303},"CVSS:3.0\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L",{"type":305,"score":306},"CVSS_V4","CVSS:4.0\u002FAV:L\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:L\u002FVI:L\u002FVA:L\u002FSC:N\u002FSI:N\u002FSA:N",[308,310,312,314,315,317],{"type":240,"url":309},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-8309",{"type":237,"url":311},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F64c317eba05fbac0c6a6fc5aa192bc0d7130972e",{"type":237,"url":313},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc2a3021bb0c5f54649d380b42a0684ca5778c255",{"type":245,"url":246},{"type":237,"url":316},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain\u002FPYSEC-2024-115.yaml",{"type":237,"url":318},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F8f4ad910-7fdc-4089-8f0a-b5df5f32e7c5",[320],"pypi:langchain-community@0.2.7",{"id":99,"slug":322,"dossier":47,"summary":323,"aliases":324,"sourceIds":327,"published":328,"modified":329,"checkedAt":7,"severity":330,"references":333,"versionKeys":348,"packageCount":32,"repositoryCount":32},"ghsa-5chr-fjjv-38qv-5f3dd755","langchain-core allows unauthorized users to read arbitrary files from the host file system",[325,326],"CVE-2024-10940","PYSEC-2026-1517",[99,326],"2025-03-20T12:32:41Z","2026-07-07T17:56:35.905913395Z",[331],{"type":233,"score":332},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[334,336,338,340,342,343,345,346],{"type":240,"url":335},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-10940",{"type":237,"url":337},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F7d481f10102f43559cc57bcad7eba291067939ee",{"type":237,"url":339},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc1e742347f9701aadba8920e4d1f79a636e50b68",{"type":237,"url":341},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fe711034713259ae448981bc0fd1d7a5671499c31",{"type":245,"url":246},{"type":237,"url":344},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fbe1ee1cb-2147-4ff4-a57b-b6045271cf27",{"type":245,"url":250},{"type":240,"url":347},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-5chr-fjjv-38qv",[254],{"id":100,"slug":350,"dossier":47,"summary":351,"aliases":352,"sourceIds":355,"published":356,"modified":357,"checkedAt":7,"severity":358,"references":361,"versionKeys":374,"packageCount":32,"repositoryCount":158},"ghsa-6qv9-48xg-fc7f-6f0bc426","LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates",[353,354],"CVE-2025-65106","PYSEC-2026-1518",[100,354],"2025-11-20T17:42:12Z","2026-09-10T03:50:30.757129019Z",[359],{"type":305,"score":360},"CVSS:4.0\u002FAV:N\u002FAC:L\u002FAT:P\u002FPR:N\u002FUI:N\u002FVC:H\u002FVI:L\u002FVA:N\u002FSC:N\u002FSI:N\u002FSA:N",[362,364,366,368,370,371,372],{"type":237,"url":363},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",{"type":240,"url":365},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-65106",{"type":237,"url":367},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fc4b6ba254e1a49ed91f2e268e6484011c540542a",{"type":237,"url":369},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Ffa7789d6c21222b85211755d822ef698d3b34e00",{"type":245,"url":246},{"type":245,"url":250},{"type":240,"url":373},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-6qv9-48xg-fc7f",[254,255,256],{"id":101,"slug":376,"dossier":47,"summary":377,"aliases":378,"sourceIds":381,"published":382,"modified":383,"checkedAt":7,"severity":384,"references":387,"versionKeys":408,"packageCount":32,"repositoryCount":34},"ghsa-926x-3r5x-gfhw-b7d12e65","LangChain has incomplete f-string validation in prompt templates",[379,380],"CVE-2026-40087","PYSEC-2026-2563",[101,380],"2026-04-08T21:51:32Z","2026-09-10T03:51:01.352737245Z",[385],{"type":233,"score":386},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[388,390,392,394,396,398,400,401,403,405,406],{"type":237,"url":389},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",{"type":240,"url":391},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-40087",{"type":237,"url":393},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36612",{"type":237,"url":395},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F36613",{"type":237,"url":397},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F6bab0ba3c12328008ddca3e0d54ff5a6151cd27b",{"type":237,"url":399},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Faf2ed47c6f008cdd551f3c0d87db3774c8dfe258",{"type":245,"url":246},{"type":237,"url":402},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.84",{"type":237,"url":404},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.28",{"type":245,"url":250},{"type":240,"url":407},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-926x-3r5x-gfhw",[254,255,256,257],{"id":102,"slug":410,"dossier":47,"summary":411,"aliases":412,"sourceIds":415,"published":416,"modified":417,"checkedAt":7,"severity":418,"references":421,"versionKeys":442,"packageCount":32,"repositoryCount":158},"ghsa-c67j-w6g6-q2cm-a4c5c0cf","LangChain serialization injection vulnerability enables secret extraction in dumps\u002Floads APIs",[413,414],"CVE-2025-68664","PYSEC-2026-373",[102,414],"2025-12-23T18:46:13Z","2026-09-10T03:50:31.915283166Z",[419],{"type":233,"score":420},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:H\u002FI:L\u002FA:N",[422,424,426,428,430,432,434,435,437,439,440],{"type":237,"url":423},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",{"type":240,"url":425},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-68664",{"type":237,"url":427},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34455",{"type":237,"url":429},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F34458",{"type":237,"url":431},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F5ec0fa69de31bbe3d76e4cf9cd65a6accb8466c8",{"type":237,"url":433},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fd9ec4c5cc78960abd37da79b0250f5642e6f0ce6",{"type":245,"url":246},{"type":237,"url":436},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D0.3.81",{"type":237,"url":438},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core%3D%3D1.2.5",{"type":245,"url":250},{"type":240,"url":441},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-c67j-w6g6-q2cm",[254,255,256],{"id":103,"slug":444,"dossier":47,"summary":445,"aliases":446,"sourceIds":449,"published":450,"modified":451,"checkedAt":7,"severity":452,"references":455,"versionKeys":463,"packageCount":32,"repositoryCount":168},"ghsa-fv5p-p927-qmxr-2692dd04","LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass",[447,448],"CVE-2026-41481","PYSEC-2026-77",[103,448],"2026-04-16T22:53:32Z","2026-09-10T03:50:44.294835049Z",[453],{"type":233,"score":454},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[456,458,460,461],{"type":240,"url":457},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-fv5p-p927-qmxr",{"type":240,"url":459},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41481",{"type":245,"url":246},{"type":237,"url":462},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain-text-splitters\u002FPYSEC-2026-77.yaml",[464,465],"pypi:langchain-text-splitters@0.3.2","pypi:langchain-text-splitters@1.1.0",{"id":104,"slug":467,"dossier":47,"summary":468,"aliases":469,"sourceIds":473,"published":474,"modified":475,"checkedAt":7,"severity":476,"references":481,"versionKeys":490,"packageCount":32,"repositoryCount":34},"ghsa-gr75-jv2w-4656-a5b8c61e","LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders",[470,471,472],"CVE-2026-55443","PYSEC-2026-2192","PYSEC-2026-2556",[104,471],"2026-06-16T15:03:14Z","2026-09-10T03:51:08.737829576Z",[477,479],{"type":233,"score":478},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":233,"score":480},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[482,484,486,489],{"type":240,"url":483},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-gr75-jv2w-4656",{"type":240,"url":485},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-55443",{"type":487,"url":488},"FIX","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002Fdcaf7795a3e6590af55c3ff7bda6add6355e9ea6",{"type":245,"url":246},[289,290,491],"pypi:langchain@1.2.6",{"id":105,"slug":493,"dossier":47,"summary":494,"aliases":495,"sourceIds":498,"published":499,"modified":500,"checkedAt":7,"severity":501,"references":506,"versionKeys":519,"packageCount":32,"repositoryCount":32},"ghsa-jw8x-6495-233v-cb32b711","scikit-learn sensitive data leakage vulnerability",[496,497],"CVE-2024-5206","PYSEC-2024-110",[105,497],"2024-06-06T19:16:00Z","2026-09-10T03:50:15.628224747Z",[502,504],{"type":233,"score":503},"CVSS:3.0\u002FAV:N\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",{"type":233,"score":505},"CVSS:3.1\u002FAV:L\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[507,509,511,513,515,517],{"type":240,"url":508},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-5206",{"type":487,"url":510},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn\u002Fcommit\u002F70ca21f106b603b611da73012c9ade7cd8e438b8",{"type":237,"url":512},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Fscikit-learn\u002FPYSEC-2024-110.yaml",{"type":245,"url":514},"https:\u002F\u002Fgithub.com\u002Fscikit-learn\u002Fscikit-learn",{"type":237,"url":516},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002F14bc0917-a85b-4106-a170-d09d5191517c",{"type":240,"url":518},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-jw8x-6495-233v",[520],"pypi:scikit-learn@1.3.2",{"id":106,"slug":522,"dossier":47,"summary":523,"aliases":524,"sourceIds":527,"published":528,"modified":529,"checkedAt":7,"severity":530,"references":533,"versionKeys":547,"packageCount":32,"repositoryCount":32},"ghsa-m42m-m8cr-8m58-f064d587","LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing",[525,526],"CVE-2025-6985","PYSEC-2026-1520",[106,526],"2025-10-06T18:31:07Z","2026-09-10T03:50:30.091012895Z",[531],{"type":233,"score":532},"CVSS:3.0\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[534,536,538,540,541,543,545],{"type":240,"url":535},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6985",{"type":237,"url":537},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F31819",{"type":237,"url":539},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F43eef435505a1c907227b724c0c760ad5fc01790",{"type":245,"url":246},{"type":237,"url":542},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fcf78abbb-df3b-43de-b6ee-132b73ff8331",{"type":245,"url":544},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-text-splitters",{"type":240,"url":546},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-m42m-m8cr-8m58",[464],{"id":107,"slug":549,"dossier":47,"summary":550,"aliases":551,"sourceIds":554,"published":555,"modified":556,"checkedAt":7,"severity":557,"references":559,"versionKeys":574,"packageCount":32,"repositoryCount":158},"ghsa-pc6w-59fv-rh23-cab9cb2f","Langchain Community Vulnerable to XML External Entity (XXE) Attacks",[552,553],"CVE-2025-6984","PYSEC-2026-1515",[107,553],"2025-09-04T12:30:42Z","2026-09-10T03:50:28.568695973Z",[558],{"type":233,"score":532},[560,562,564,566,568,570,572],{"type":240,"url":561},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2025-6984",{"type":237,"url":563},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community\u002Fcommit\u002Fe842452108089524e22c3a2ced851c021884556f",{"type":245,"url":565},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain-community",{"type":237,"url":567},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fblob\u002Fd79b5813a0b3b243c612b77013768995e46c4337\u002Flibs\u002Flangchain\u002Flangchain\u002Fdocument_loaders\u002Fevernote.py#L1-L23",{"type":237,"url":569},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fa6b521cf-258c-41c0-9edb-d8ef976abb2a",{"type":245,"url":571},"https:\u002F\u002Fpypi.org\u002Fproject\u002Flangchain-community",{"type":240,"url":573},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pc6w-59fv-rh23",[320,575,576],"pypi:langchain-community@0.3.5","pypi:langchain-community@0.3.7",{"id":108,"slug":578,"dossier":47,"summary":579,"aliases":580,"sourceIds":583,"published":584,"modified":585,"checkedAt":7,"severity":586,"references":589,"versionKeys":598,"packageCount":32,"repositoryCount":34},"ghsa-pjwx-r37v-7724-2297a72a","LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists",[581,582],"CVE-2026-44843","PYSEC-2026-2564",[108,582],"2026-05-08T23:07:32Z","2026-09-10T03:51:06.718716596Z",[587],{"type":233,"score":588},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:L\u002FA:N",[590,592,594,595,596],{"type":237,"url":591},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",{"type":240,"url":593},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-44843",{"type":245,"url":246},{"type":245,"url":250},{"type":240,"url":597},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-pjwx-r37v-7724",[254,255,256,257],{"id":109,"slug":600,"dossier":47,"summary":601,"aliases":602,"sourceIds":605,"published":606,"modified":607,"checkedAt":7,"severity":608,"references":611,"versionKeys":626,"packageCount":32,"repositoryCount":32},"ghsa-q25c-c977-4cmh-8e74e348","Server-Side Request Forgery in langchain-community.retrievers.web_research.WebResearchRetriever",[603,604],"CVE-2024-3095","PYSEC-2026-1516",[109,604],"2024-06-06T21:30:36Z","2026-07-07T17:57:27.127785500Z",[609],{"type":233,"score":610},"CVSS:3.0\u002FAV:P\u002FAC:H\u002FPR:L\u002FUI:N\u002FS:C\u002FC:H\u002FI:N\u002FA:N",[612,614,616,618,619,621,623,624],{"type":240,"url":613},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2024-3095",{"type":237,"url":615},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fpull\u002F24451",{"type":237,"url":617},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F604dfe2d99246b0c09f047c604f0c63eafba31e7",{"type":245,"url":246},{"type":237,"url":620},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-community%3D%3D0.2.9",{"type":237,"url":622},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Fe62d4895-2901-405b-9559-38276b6a5273",{"type":245,"url":571},{"type":240,"url":625},"https:\u002F\u002Fgithub.com\u002Fadvisories\u002FGHSA-q25c-c977-4cmh",[320],{"id":110,"slug":628,"dossier":47,"summary":629,"aliases":630,"sourceIds":633,"published":634,"modified":635,"checkedAt":7,"severity":636,"references":639,"versionKeys":661,"packageCount":32,"repositoryCount":34},"ghsa-qh6h-p6c9-ff54-caf42ff5","LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions",[631,632],"CVE-2026-34070","PYSEC-2026-2193",[110,632],"2026-03-27T19:45:00Z","2026-09-10T03:50:40.646863770Z",[637],{"type":233,"score":638},"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:N\u002FA:N",[640,643,645,647,648,650,652,654,656,658],{"type":641,"url":642},"EVIDENCE","https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-qh6h-p6c9-ff54",{"type":240,"url":644},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-34070",{"type":487,"url":646},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fcommit\u002F27add913474e01e33bededf4096151130ba0d47c",{"type":245,"url":246},{"type":240,"url":649},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Freleases\u002Ftag\u002Flangchain-core==1.2.22",{"type":237,"url":651},"https:\u002F\u002Faccess.redhat.com\u002Fsecurity\u002Fcve\u002FCVE-2026-34070",{"type":237,"url":653},"https:\u002F\u002Fsecurity.access.redhat.com\u002Fdata\u002Fcsaf\u002Fv2\u002Fvex\u002F2026\u002Fcve-2026-34070.json",{"type":240,"url":655},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:24766",{"type":240,"url":657},"https:\u002F\u002Faccess.redhat.com\u002Ferrata\u002FRHSA-2026:37275",{"type":659,"url":660},"REPORT","https:\u002F\u002Fbugzilla.redhat.com\u002Fshow_bug.cgi?id=2453287",[254,255,256,257],{"id":111,"slug":663,"dossier":47,"summary":664,"aliases":665,"sourceIds":668,"published":669,"modified":670,"checkedAt":7,"severity":671,"references":674,"versionKeys":682,"packageCount":32,"repositoryCount":34},"ghsa-r7w7-9xr2-qq2r-7a3a0a91","langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding",[666,667],"CVE-2026-41488","PYSEC-2026-76",[111,667],"2026-04-16T23:00:12Z","2026-06-06T01:15:07.912179267Z",[672],{"type":233,"score":673},"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:N\u002FUI:R\u002FS:U\u002FC:L\u002FI:N\u002FA:N",[675,677,679,680],{"type":240,"url":676},"https:\u002F\u002Fgithub.com\u002Flangchain-ai\u002Flangchain\u002Fsecurity\u002Fadvisories\u002FGHSA-r7w7-9xr2-qq2r",{"type":240,"url":678},"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41488",{"type":245,"url":246},{"type":237,"url":681},"https:\u002F\u002Fgithub.com\u002Fpypa\u002Fadvisory-database\u002Ftree\u002Fmain\u002Fvulns\u002Flangchain-openai\u002FPYSEC-2026-76.yaml",[683,684,685,686],"pypi:langchain-openai@0.2.8","pypi:langchain-openai@0.3.0","pypi:langchain-openai@1.1.7","pypi:langchain-openai@1.1.9",{"id":113,"slug":688,"dossier":47,"summary":137,"aliases":689,"sourceIds":693,"published":694,"modified":695,"checkedAt":7,"severity":696,"references":699,"versionKeys":703,"packageCount":32,"repositoryCount":32},"pysec-2024-323-1dd96856",[690,691,692],"CVE-2024-5998","GHSA-f2jm-rw3h-6phg","PYSEC-2026-1514",[113],"2024-09-17T12:15:02.977Z","2026-07-13T07:26:23.643495355Z",[697],{"type":233,"score":698},"CVSS:3.1\u002FAV:L\u002FAC:L\u002FPR:N\u002FUI:R\u002FS:U\u002FC:H\u002FI:H\u002FA:H",[700,701],{"type":487,"url":617},{"type":641,"url":702},"https:\u002F\u002Fhuntr.com\u002Fbounties\u002Ffa3a2753-57c3-4e08-a176-d7a3ffda28fe",[289],1790757844830]