BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

LangChain ‘LangGrinch’ Flaw Lets Attackers Steal Secrets Now

Critical LangChain Core serialization injection (CVE-2025-68664) can expose secrets and enable prompt/Jinja2-based code execution — update to 1.2.5/0.3.81.

  • LangChain Core contains a critical serialization injection flaw (CVE-2025-68664, CVSS 9.3) that can expose secrets and enable prompt injection.
  • The bug stems from improper escaping of dictionaries with “lc” keys during serialization and deserialization in the library’s dump/load functions.
  • Patches restrict allowed deserialized objects, disable automatic secret loading, and block Jinja2 templates by default; affected versions should be updated immediately.

LangChain Core, the Python core package for LangChain, contains a critical vulnerability disclosed in December 2025 that can let attackers extract secrets and influence LLM outputs. Security researcher Yarden Porat reported the issue on December 4, 2025; it is tracked as CVE-2025-68664 with a CVSS score of 9.3 and nicknamed LangGrinch. See the LangChain Core reference and the 1.2.5 package details.

- Advertisement -

The maintainers said the flaw is a problem in the library’s serialization functions, noting that “A serialization injection vulnerability exists in LangChain’s dumps() and dumpd() functions” in their advisory. A serialization injection vulnerability is when an attacker supplies specially crafted serialized data that is interpreted as executable or structured objects during deserialization.

The code fails to escape user-controlled dictionaries that include an “lc” key, which the framework uses internally to mark serialized objects. According to Porat, that lets an attacker cause the system to instantiate unsafe objects when content with an “lc” key is serialized and later deserialized.

Potential outcomes include extraction of environment secrets when deserialization runs with the previous default secrets_from_env=True, instantiation of classes in trusted namespaces (such as langchain_core, langchain, and langchain_community), and possible arbitrary code execution via Jinja2 templates. The escaping bug also enables injection through LLM output fields like metadata, additional_kwargs, or response_metadata.

The patch adds an allowlist parameter “allowed_objects” to restrict deserialized classes, blocks Jinja2 templates by default, and sets secrets_from_env to False. Affected langchain-core versions are >= 1.0.0, < 1.2.5 (fixed in 1.2.5) and < 0.3.81 (fixed in 0.3.81).

- Advertisement -

A related serialization injection issue affects LangChain.js and carries CVE-2025-68665 (CVSS 8.6); see the advisory for affected npm package versions and fixes. Users are advised to update to patched releases as soon as possible.

“The most common attack vector is through LLM response fields like additional_kwargs or response_metadata, which can be controlled via prompt injection and then serialized/deserialized in streaming operations,” Porat said in his write-up.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Foundation Proposes Unified Layer-2 Zone

Developers from Gnosis and Zisk, backed by the Ethereum Foundation, have proposed the "Ethereum...

Nations Push De-Dollarization to Hedge Against U.S. Debt Risk

Several nations are actively de-dollarizing to hedge against U.S. financial instability, driven by the...

Worldcoin sells $65M tokens at discount as price hits record low

The World Foundation sold 239 million WLD tokens via an over-the-counter sale, raising $65...

Onchain Commodity Trading Hits $5.4B Amid Liquidity Limits

Onchain commodity trading on Hyperliquid hit a new all-time high of $5.4 billion in...

Shibarium: Shiba Inu’s Sleeping Giant or Failed Launch?

Shiba Inu launched its Shibarium layer-2 network in August 2023, which did not immediately...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading