A newly disclosed critical security vulnerability in the LangChain Core framework — a foundational component used to build applications powered by large language models (LLMs) — has raised alarm bells across the cybersecurity and AI development communities. Tracked as CVE-2025-68664 and dubbed LangGrinch, the flaw could allow attackers to steal sensitive secrets and manipulate AI behavior through unsafe handling of serialized data, according to researchers and advisory disclosures.

What’s at Stake: Secrets, Prompt Injection, and More

LangChain Core, the core Python package powering many AI agents and workflows, is affected by a high-severity serialization injection vulnerability that carries a CVSS score of 9.3 out of 10, indicating strong potential for real-world exploitation.

At its core, the issue stems from how LangChain’s dumps() and dumpd() serialization functions handle user-controlled data structures, especially those containing an internal marker key ("lc"). When untrusted inputs are not properly escaped during serialization, they may be wrongly interpreted as legitimate internal objects during deserialization — opening the door for attackers to instantiate unsafe objects or extract secrets from environment variables.

Security researcher Yarden Porat — credited with the discovery — explained that this unsafe deserialization process can be triggered via LLM outputs, like metadata fields or additional streams from model responses, effectively turning a harmless text prompt into a potential exploit vector.

This means an attacker who can influence LLM output — for example through prompt injection — might embed harmful structures that later get processed inside serialization logic, potentially leading to:

  • Secret exfiltration (e.g., API keys, environment variables),
  • Unauthorized object instantiation,
  • Arbitrary code execution via template engines like Jinja2, and
  • Manipulation of AI agent behavior or other logic flows.

Versions Affected and Immediate Mitigation

The vulnerability affects both Python and JavaScript ecosystems of LangChain, meaning a broad swath of applications could be at risk unless updated promptly.

Affected LangChain Versions

  • Python (langchain-core):
    • Versions >=1.0.0 and <1.2.5
    • Versions <0.3.81
      – Fixed in 1.2.5 and 0.3.81
  • JavaScript variants (similar flaw tracked as CVE-2025-68665 with CVSS 8.6) impact:
    • @langchain/core >= 1.0.0 and <1.1.8
    • @langchain/core < 0.3.80
    • langchain >= 1.0.0 and <1.2.3
    • langchain < 0.3.37
      – All fixed in newer versions

To mitigate this risk, the LangChain team has updated how serialization is handled by introducing restrictive defaults, including:

  • Allowlist controls (allowed_objects) to limit which classes can be serialized/deserialized,
  • Blocking risky templates like Jinja2 by default, and
  • Disabling automatic secret loading from environment variables unless explicitly allowed.

Developers are strongly urged to upgrade to the patched releases immediately, especially if their workflows include untrusted inputs, LLM streaming operations, or any dynamic serialization logic.

Why This Matters: AI and Traditional Security Collide

The LangGrinch vulnerability highlights a deeper issue at the intersection of AI development and classic security principles: LLM outputs should be treated as untrusted inputs. Unlike traditional software data flows, where strict typing and validation can be applied throughout, AI systems often produce outputs influenced by external inputs or model artifacts — making them fertile ground for injection attacks if unguarded.

In this case, fields such as additional_kwargs or response_metadata, often used to capture LLM behavior or metadata, can serve as unwitting avenues for attackers to embed harmful structures that bypass safety checks.

Industry experts warn that frameworks underpinning AI agents and automated workflows must adopt defense-in-depth strategies, including:

  • Treating all AI output as potentially malicious,
  • Applying strict validation and sanitization,
  • Avoiding broad serialization permissions, and
  • Isolating sensitive operations from LLM-driven logic. LangChain Docs

As AI continues to weave deeper into business logic and automation, these approaches become crucial to mitigating emergent risks that blur the lines between AI misbehavior and conventional security exploits.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *