PyPI: langchain
GHSA-gr75-jv2w-4656
Safety vulnerability ID: SFTY-20260616-96324
Affected versions of the LangChain components are vulnerable to Path Traversal due to improper validation of resolved filesystem paths. The file-search middleware and configuration loaders fail to confine resolved paths to the intended root directory, allowing glob patterns and symlinks to access files outside the configured root. An attacker can exploit this by providing crafted path values or search patterns, potentially leading to the unauthorized disclosure of files outside their intended boundaries.
Overview
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
Advisory
langchain components – Path Traversal
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260616-96324
- https://github.com/langchain-ai/langchain/security/advisories/GHSA-gr75-jv2w-4656
- https://nvd.nist.gov/vuln/detail/CVE-2026-55443
- https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6
- https://github.com/advisories/GHSA-gr75-jv2w-4656
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
