Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-34540 Langchain OS Command Injection vulnerabilityCVE-2023-34541 Langchain vulnerable to arbitrary code executionCVE-2023-36095 langchain Code Injection vulnerabilityCVE-2023-36188 langchain vulnerable to arbitrary code executionCVE-2023-36258 langchain arbitrary code execution vulnerabilityCVE-2023-36281 langchain vulnerable to arbitrary code executionCVE-2023-38860 LangChain vulnerable to arbitrary code executionCVE-2023-38896 LangChain vulnerable to arbitrary code executionCVE-2023-39631 Langchain vulnerable to arbitrary code execution via the evaluate function in the numexpr libraryCVE-2023-39659 LangChain vulnerable to arbitrary code executionCVE-2023-32786 Langchain Server-Side Request Forgery vulnerabilityCVE-2023-36189 langchain SQL Injection vulnerabilityCVE-2023-46229 langchain: langchain SSRFCVE-2026-45134 LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningCVE-2024-2965 langchain-community: Langchain-community SitemapParser DoS VulnerabilityCVE-2024-3571 langchain vulnerable to path traversalCVE-2026-55443 LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loadersCVE-2025-64512 Pdfminer.six is a community maintained fork of the original PDFMiner, ...CVE-2025-70559 pdfminer.six before 20251230 contains an insecure deserialization vuln ...CVE-2022-1941 protobuf: message parsing vulnerability in ProtocolBuffersCVE-2025-4565 python-protobuf: Unbounded recursion in Python ProtobufCVE-2026-0994 python: protobuf: Protobuf: Denial of Service due to recursion depth bypassCVE-2023-43804 python-urllib3: Cookie request header isn't stripped during cross-origin redirectsCVE-2025-66418 urllib3: urllib3: Unbounded decompression chain leads to resource exhaustionCVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed dataYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2023-109 An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method.PYSEC-2023-138 An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_objePYSEC-2023-145 An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.PYSEC-2023-146 An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.PYSEC-2023-147 An issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component.PYSEC-2023-151 An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via the via the a json file to the load_prompt parameter.PYSEC-2023-162 An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.PYSEC-2023-91 Langchain 0.0.171 is vulnerable to Arbitrary Code Execution.PYSEC-2023-92 Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.PYSEC-2023-98 An issue in langchain v.0.0.199 allows an attacker to execute arbitrary code via the PALChain in the python exec method.PYSEC-2026-372 Langchain SQL Injection vulnerabilityPYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in respPYSEC-2023-110 SQL injection vulnerability in langchain v.0.0.64 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component.PYSEC-2023-205 LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server.PYSEC-2024-118 A Denial-of-Service (DoS) vulnerability exists in the `SitemapLoader` class of the `langchain-ai/langchain` repository, affecting all versions. The `parse_sitemap` method, responsible for parsing sitePYSEC-2024-323 A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via thePYSEC-2026-1507 Langchain SQL Injection vulnerabilityPYSEC-2026-1508 Langchain Server-Side Request Forgery vulnerabilityPYSEC-2026-1510 langchain vulnerable to path traversalPYSEC-2026-2192 LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently confPYSEC-2026-2555 LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warningPYSEC-2026-1805 protobuf affected by a JSON recursion depth bypassPYSEC-2026-1806 protobuf-python has a potential Denial of Service issuePYSEC-2026-899 protobuf-cpp and protobuf-python have potential Denial of Service issuePYSEC-2023-192 urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of tCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.