PyPI: langchain

GHSA-gr75-jv2w-4656

Safety vulnerability ID: SFTY-20260616-96324

Affected versions of the LangChain components are vulnerable to Path Traversal due to improper validation of resolved filesystem paths. The file-search middleware and configuration loaders fail to confine resolved paths to the intended root directory, allowing glob patterns and symlinks to access files outside the configured root. An attacker can exploit this by providing crafted path values or search patterns, potentially leading to the unauthorized disclosure of files outside their intended boundaries.

Created at: Jun 16, 2026Updated at: Jun 16, 2026

Overview

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

Advisory

langchain components – Path Traversal

Affected Package

Affecting langchain package, versions
<= 1.3.8

Also affects

---

How to Fix

Upgrade
langchain
to
1.3.9
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more