
Critical 9.3 Severity LangChain Serialization Flaw Enables Secret Theft
A critical vulnerability (CVE-2025-68664, CVSS 9.3) was disclosed affecting the LangChain open-source LLM framework, allowing attackers to steal sensitive data and potentially trigger unintended actions via prompt injection. Due to the potential for environment variable exposure and unauthorized logic execution, immediate patching is required. The issue originates from LangChain’s (and LangChain Core’s) data serialization logic, …











